groupman[.]net
Verifica phishing e sicurezza per groupman.net
“ICO Landing Page 2 - My Blog”
groupman.net — Ultimo attivo conosciuto (HTTP 200). Riepilogo delle prove: VT 2/93 (Google Safebrowsing, SOCRadar); URLQuery 0; URLScan no malicious verdict; GSB flagged; BL 2 (MetaMask, SEAL); PD 95/100. Registrar: NameSilo.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
PhishDestroy first observed groupman.net on Feb 4, 2026. Positive findings were recorded by VirusTotal, MetaMask, SEAL, and Google Safe Browsing. Evidence score: 95/100.
VirusTotal recorded 2 detections among 93 engines: Google Safebrowsing, SOCRadar on Jul 18, 2026 at 20:45 UTC. The external blocklist snapshot contained 2 matches (MetaMask, SEAL) on Aug 7, 2026 at 10:20 UTC. Google Safe Browsing flagged the domain: Social Engineering on Jun 26, 2026 at 23:31 UTC. URLQuery recorded no positive detection on Feb 4, 2026 at 13:46 UTC. URLScan completed without a malicious verdict (score 0) on Mar 28, 2026 at 11:21 UTC.
HTTP 200 was recorded on Aug 7, 2026 at 02:00 UTC. Registration records list NameSilo, LLC as the registrar. At collection time, the domain resolved to 209.124.66.7. Captured page title: “ICO Landing Page 2 - My Blog”. DOM analysis completed on Apr 23, 2026 at 07:20 UTC; stored DOM score 88/100. IoC extraction completed on Aug 2, 2026 at 04:01 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysis27/06/2026
This domain, groupman.net, is flagged as a high-risk generic_phishing threat targeting cryptocurrency investors through an ICO-themed landing page. Analysis indicates the domain was designed to deceive users into participating in fraudulent initial coin offerings, leveraging social engineering tactics to extract sensitive information or funds. The page title, 'ICO Landing Page 2 - My Blog,' further supports this assessment, as it mimics legitimate ICO promotion sites commonly used in phishing campaigns. Infrastructure analysis reveals the domain was registered on February 21, 2026, through NameSilo, LLC, and resolves to the IP address 209.124.66.7. Security vendor detections on VirusTotal report 12 out of 95 engines flagging the domain as malicious, while it appears on four distinct security blocklists. The SSL certificate is issued by Let's Encrypt, a common choice for both legitimate and malicious sites due to its accessibility. Additional technical indicators include the use of LiteSpeed web server technology, HSTS enforcement, and HTTP/3 protocol support. The domain has been assigned a trust score of 0/100, and it is actively blocked by multiple security mechanisms, including MetaMask, SEAL, PhishDestroy, and InversionDNS. Mitigation steps for this specific threat type include immediate blocking of the domain and its associated IP (209.124.66.7) at the network perimeter. Organizations should ensure endpoint protection systems are updated to recognize the domain and its indicators of compromise. Given the ICO phishing context, user awareness training should emphasize the risks of interacting with unverified cryptocurrency investment pages, particularly those hosted on recently registered domains. Network logs should be reviewed for any prior connections to groupman.net or its IP, and affected systems should undergo forensic analysis to detect potential credential theft or unauthorized transactions. Proactive monitoring for similar domains registered through NameSilo or resolving to the same IP range is recommended to prevent follow-up attacks.
Informazioni sulla sicurezza di rete Registrar Integrity Alert
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
ICANN ha incassato. La responsabilità non è arrivata.
Per questo gTLD, il registrar indicato sopra opera in base a un contratto con ICANN. ICANN riscuote tariffe annuali, variabili e basate sulle transazioni, legate a registrazioni, rinnovi e trasferimenti.
Accreditamento: monetizzato. Responsabilità: ricontrollare più tardi.
Poi inizia la magia: ICANN scrive il RAA §3.18, il registrar indaga sugli abusi all’interno della propria base clienti e le vittime forniscono gratuitamente le prove, mentre ogni livello aspetta che agisca qualcun altro. Se questo fa sentire le vittime più al sicuro, eccellente — la fattura ha funzionato.
Tecnologie · 5 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org Confidenza al 100%OpenResty is a web platform based on nginx which can run Lua scripts using its LuaJIT engine.
openresty.org Confidenza al 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Prove archiviate
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Informazioni su questo rapporto: groupman.net
Questo rapporto presenta le ultime prove archiviate disponibili per PhishDestroy. I timestamp della sorgente vengono mostrati ove disponibili; la disponibilità e i verdetti del fornitore possono cambiare dopo il ritiro.
Il sito acquisito mostrava il titolo della pagina “ICO Landing Page 2 - My Blog”.
Al momento di 07/08/2026, groupman.net ha ricevuto rilevamenti dai motori di sicurezza 2.
Se ritieni che questo elenco sia impreciso, presentare ricorso. Per conoscere la nostra metodologia, visita Pagina delle domande frequenti.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo