pc[.]gtcfxlgroup[.]cc
“GTCFX”
Riepilogo delle prove
Analysis of pc.gtcfxlgroup.cc confirms its classification as a high-risk phishing domain targeting users associated with the GTCFX brand, as indicated by the page title and Google Safe Browsing's social engineering flag. The domain was registered on January 6, 2026, through Gname.com Pte. Ltd., and currently resolves to IP 172.67.173.68, hosted on Cloudflare's network (AS13335). Infrastructure analysis reveals the use of Cloudflare nameservers (eve.ns.cloudflare.com, hasslo.ns.cloudflare.com) and technologies including Ant Design, Vue.js, Cloudflare Browser Insights, and HTTP/3, suggesting a modern, potentially obfuscated phishing kit. The domain is flagged by 16 of 94 security vendors on VirusTotal, with additional detections from PhishDestroy, MetaMask, and SEAL blocklists.
Gridinsoft assigns a trust score of 0/100, further corroborating its malicious status. At the time of this report, the domain returns an HTTP 403 status, indicating it may have been taken offline or restricted by the hosting provider. It appears on three security blocklists, and Google Safe Browsing explicitly categorizes it as engaging in social engineering. Defenders should treat this domain as confirmed malicious and prioritize blocking it at the DNS and network levels.
The SSL certificate (WE1) and Cloudflare hosting are consistent with phishing campaigns leveraging CDN services to evade detection. While the exact content of the phishing pages is not yet analyzed, the combination of brand impersonation, low trust scores, and multi-vendor detections justifies immediate action. Organizations should monitor for related domains registered under the same registrar or using identical nameserver patterns, as these may indicate follow-up campaigns.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
8 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
VirusTotal
0 → 13
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
Tecnologie
5 tecnologie identificate con alta affidabilità
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo