grow-right[.]ltd
“grow-right.ltd”
grow-right.ltd — Conteúdo indisponível. Representação da marca: Coinbase. Resumo das evidências: VirusTotal 2/95 (Netcraft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain grow-right.ltd was registered on February 21, 2026 and is currently reported as taken offline. DNS resolution points to the IP address 198.251.88.6, which is announced by AS53667 FranTech Solutions and geolocated to the United States. The authoritative nameservers are ns1.my-control-panel.com and ns2.my-control-panel.com, indicating the use of a generic control‑panel hosting service. The site’s HTML title tag reads "grow-right.ltd," providing no additional context about the content or intended victim demographic. No SSL certificate is associated with the domain, leaving the HTTP connection unencrypted and exposing any transmitted credentials to interception.
Threat intelligence flags the domain as a generic phishing indicator. It appears on three public blocklists and is specifically blocked by the PhishDestroy, MetaMask, and SEAL filtering platforms. VirusTotal analysis shows that 2 of 95 security vendors have flagged the domain, suggesting that at least a minority of scanners have identified malicious characteristics. The absence of a certificate, combined with the blocklist presence and the limited VirusTotal detections, aligns with typical infrastructure used for credential‑harvesting campaigns. Uncertainty remains regarding the exact phishing payload, target brand, or victim interaction flow because the page content has not been captured.
Defenders should continue to block connections to 198.251.88.6 and add grow-right.ltd to URL filtering rules. Monitoring of the associated nameservers and ASN for any reactivation is advisable. Since the domain is offline, threat actors may redeploy the same infrastructure under a new domain; therefore, threat‑intel teams should watch for similarly configured domains using the same nameserver pattern or ASN. Continuous re‑evaluation of blocklist status and periodic VirusTotal rescans are recommended to capture any changes in malicious activity.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo