SUSPICIOUS — FLAGGED
grok26k[.]com
PhishDestroy identifies grok26k.com as an active credential theft phishing domain used to harvest user login details and sensitive information.
- VirusTotal
- 0 detections
- Blocklists
- No stored match
- Ketersediaan
- Konten tidak tersedia · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
grok26k.com — Konten tidak tersedia (HTTP 502). Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 0 detections (engine total unavailable); PhishDestroy score 48/100. Registrar: Ultahost.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Analysis
PhishDestroy identifies grok26k.com as an active credential theft phishing domain used to harvest user login details and sensitive information. The site remains under investigation but continues to operate with confirmed malicious intent. No specific brand impersonation has been confirmed at this stage of analysis.
This domain was flagged by 0 of 95 VirusTotal vendors as of the latest scan, indicating low detection despite its active threat status. grok26k.com is registered through Ultahost, Inc., resolves to IP 99.83.231.61, and holds a Let's Encrypt SSL certificate issued for web security obfuscation. The domain was created on May 17, 2026—a recent registration timeline suggesting opportunistic deployment. It has not yet appeared on major threat intelligence blocklists, and real-time trust scores remain uncompromised. However, the absence of detections should not be interpreted as safety, particularly given the active credential theft operation under investigation.
Authorities recommend immediate network and endpoint blocking of grok26k.com and IP 99.83.231.61. Organizations should audit outbound traffic to prevent data exfiltration and warn users against interacting with the domain. Deployments of browser-based security extensions that block known phishing vectors are strongly advised. Continuous monitoring via threat intelligence feeds for emerging blocks is essential. Administrators are urged to update firewall rules, DNS sinkholes, and email filtering systems to block all communications with the domain and associated infrastructure. Given the low VT detection rate, this domain represents a high-risk, high-impact threat vector requiring urgent containment action.
Cakupan data12 recorded checks
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknologi · 7 identified
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
wordpress.org Keyakinan 100%Tidio is a customer communication product. It provides multi-channel support so users can communicate with customers on the go. Live chat, messenger, or email are all supported.
www.tidio.com Keyakinan 100%Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com Keyakinan 100%jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com Keyakinan 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Keyakinan 100%Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of grok26k.com · checked May 18, 2026
Bukti & Laporan EksternalIndependent lookups and source reports
PD-20260518-8F7B3D Recipient: abuse@ultahost.com Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.