gro83k[.]net
“GRO83K Token – Official Presale Website - Up to 200% Early Participation Bonus”
gro83k.net — 마지막으로 알려진 활성 (HTTP 200). 사기 유형: Investment Scam. 증거 요약: VirusTotal 5/91 (alphaMountain.ai, Bfore.Ai PreCrime, CRDF, Gridinsoft, SOCRadar); PhishDestroy score 80/100. 등록기관: Tucows.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
The domain gro83k.net was registered on May 08, 2026 through Tucows Domains Inc. and is currently flagged as an active generic phishing site targeting investors. Analysis of the page title – “GRO83K Token – Official Presale Website - Up to 200% Early Participation Bonus” – aligns with the reported scam type of an investment‑scam token presale, where promises of high early‑participation returns are used to lure victims.
Infrastructure inspection shows the domain resolves to the IPv4 address 99.83.231.61, hosted on an AWS Global Accelerator endpoint located in the United States. The site presents a valid Let’s Encrypt certificate (issuer E8) and is served over HTTPS, which may increase user confidence. Nameservers are set to anton.ns.cloudflare.com and eva.ns.cloudflare.com, indicating use of Cloudflare DNS services. Reputation scoring from Gridinsoft assigns a trust score of 0 out of 100, and the domain appears on a single security blocklist, where it has already been listed by PhishDestroy. An AlienVault OTX pulse references the domain in one threat‑intel record, reinforcing its association with malicious activity.
Technical evidence includes an HTTP 200 response indicating the page is reachable, and the lack of detections on VirusTotal (0/95) should not be interpreted as a safety indicator, as many phishing sites evade automated scanners. The combination of a newly created domain, low trust score, and presence on a blocklist, together with the investment‑centric lure, strongly suggests a credential‑harvesting or financial‑fraud operation.
Defenders should add gro83k.net to network and email deny lists, monitor for related DNS queries, and consider sinkholing the associated IP address. Continuous threat‑intel feeds should be consulted for any emerging indicators, and user awareness campaigns should highlight the specific claim of a “200% early participation bonus” as a typical lure used by this campaign.
위협 대응 Pipeline
공개 차단 목록 상태
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
ICANN OVERSIGHT
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 분석
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.