gro92k[.]icu
“GRO92K Official Pre-Sale — Get Up to 100% Bonus!”
gro92k.icu — Непроверенный. Олицетворение бренда: Genericcrypto. Сводка доказательств: VirusTotal 6/93 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This report details the technical threat assessment for the domain gro92k.icu. The site presents itself as a pre-sale opportunity for a brand or entity named "GRO92K," offering a 100% bonus. This is characteristic of a fraudulent investment or cryptocurrency scam, designed to lure victims with the promise of high returns to steal funds or personal information. The page title explicitly states "GRO92K Official Pre-Sale — Get Up to 100% Bonus!" confirming the deceptive financial incentive.
Technical analysis reveals significant indicators of malicious activity. VirusTotal reports 6 detections out of 95 security vendors, with flags from alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet, and Gridinsoft. The domain is registered with NiceNIC International Group Co., Limited, a registrar often associated with suspicious domains. The IP address 104.21.73.167 is located in the United States and is hosted by AS13335 Cloudflare, Inc. The domain was created on 2026-02-21, making it very recent. SSL certificate is issued by Google Trust Services for WE1, and nameservers are dale.ns.cloudflare.com and uma.ns.cloudflare.com.
The current status of gro92k.icu is BANNED. GridinSoft assigns a trust rating of 0 out of 100. The site is listed on 1 blocklist. The combination of a newly registered domain, high volume of vendor detections, low trust score, and banned status indicates a high risk. This site should be considered an active threat and blocked to prevent user interaction.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ЗОНА SHORTDOT · ПУБЛИЧНЫЕ ДОКАЗАТЕЛЬСТВА
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-13 03:03:21 UTC
Технологии · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
PD-20260214-96307D Recipient: abuse@nicenic.net Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание