grok66k[.]pro
“GROK66K Official Pre-Sale — Get Up to 200% Bonus!”
grok66k.pro — Não verificado. Representação da marca: Genericcrypto. Resumo das evidências: VirusTotal 13/93 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Registrador: NiceNIC.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
grok66k.pro was observed hosting a page titled “GROK66K Official Pre‑Sale — Get Up to 200% Bonus!”. The site was taken offline before this analysis, but historical data indicate it was actively serving content that promoted a pre‑sale offering with an inflated bonus, a pattern commonly associated with phishing campaigns that lure victims with unrealistic financial incentives. The domain resolves to 188.114.96.3, an IP address owned by AS13335 Cloudflare, Inc., located in the United States. Cloudflare’s reverse DNS and the presence of the nameservers jade.ns.cloudflare.com and nero.ns.cloudflare.com confirm that the domain leveraged Cloudflare’s CDN and HTTP/3 capabilities. The TLS certificate was issued by Google Trust Services under the WE1 brand, providing a legitimate‑looking HTTPS connection that can increase user trust.
Reputation checks are uniformly negative. The Gridinsoft trust score is 0 out of 100, and the domain appears on one security blocklist. PhishDestroy has already blocked the domain, and VirusTotal reports that 13 of 93 scanning engines flagged the site, indicating a moderate level of consensus among security vendors. The registrar listed is NiceNIC International Group Co., Limited, a provider that has been associated with rapid registration of abusive domains in the past.
Given the offline status, direct investigation of the live payload is not possible, and the exact content of the page beyond the title remains unknown. The limited number of vendor detections and the single blocklist entry suggest that the host may have been in an early stage of deployment or that detection signatures have not yet fully converged. Defenders should continue to block the IP address 188.114.96.3 and the associated Cloudflare nameservers, ensure that outbound traffic to the domain is denied, and monitor for any new domains that resolve to the same IP range.
Inteligência de segurança de rede Registrar context
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-14 03:06:45 UTC
Tecnologias · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo