geteegztd[.]store
“Маркет - Getgems”
Сводка доказательств
On 21 February 2026 the domain geteegztd.store was registered through the REGRU‑RU registrar and assigned the Russian name servers ns1.reg.ru and ns2.reg.ru. The domain resolves to the IPv4 address 31.57.34.181, which is announced by AS207994 (Blockchain Creek B.V.) and geolocated to the Netherlands. No TLS certificate is presented; the web service responded over HTTP/3 without encryption, which is atypical for credential‑stealing sites that usually employ HTTPS to gain user trust. The only visible page element captured is the title “Маркет – Getgems”, which does not reference the targeted brand. Nevertheless, the intelligence set classifies the campaign as a brand‑impersonation attempt against Telegram, indicating that the operator likely intends to lure Telegram users to a counterfeit service.
VirusTotal analysis recorded 2 detections out of 93 scanned security vendors, confirming that at least a minority of scanners flagged the domain as malicious. Independent reputation services assign a Gridinsoft trust score of 0 / 100 and list the domain on a single public blocklist. PhishDestroy has already taken the domain offline and added it to its blocklist, reducing immediate exposure but not guaranteeing that the infrastructure will not be reused. The limited evidence leaves several aspects uncertain: the exact phishing kit, the presence of credential‑capture forms, and any additional hosting infrastructure beyond the single IP are not publicly disclosed.
Defenders should therefore treat the domain as a confirmed malicious indicator. Recommended actions include adding geteegztd.store and its resolving IP 31.57.34.181 to network‑level deny lists, monitoring the registrar REGRU‑RU for new registrations that reuse the same name‑server pattern, and updating URL‑filtering rules to block any future resolution to the same host.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260206-C7B047- PDF-файл
- PDF с доказательствами
Полный текст доказательств
Policy Violations: Abuse policy + ICANN contractual obligations; phishing classified as bad-faith use in UDRP; domains may be suspended/removed
Applicable Laws: Criminal Code RF Art.159 (fraud), Art.272 (illegal access), Art.273 (malware creation), Art.274.1 (critical infrastructure interference)
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии
Выявлена 1 технология с высокой уверенностью
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание