grok15k[.]com
Проверка домена grok15k.com на фишинг и безопасность
“Default Web Site Page”
grok15k.com — Контент недоступен (HTTP 502). Сводка доказательств: VirusTotal 1/93 (SOCRadar); PhishDestroy score 56/100. Регистратор: NameSilo.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
Analysis of grok15k.com shows an active phishing infrastructure that was brought offline prior to this report. The domain was registered on 27 February 2026 through NameSilo, LLC and resolves to the IPv4 address 195.66.213.55. That address is assigned to SOLLUTIUM EU Sp z.o.o. in the Netherlands and is announced by ASN 43641.
No TLS certificate was observed for the domain, meaning any client connections would be unencrypted HTTP. When accessed, the site returned a generic placeholder with the page title "Default Web Site Page," indicating that the landing page either never hosted malicious content or was removed before capture. VirusTotal scans recorded a single detection out of ninety‑three security vendors, and the domain appears on one external blocklist. PhishDestroy has also listed the domain, and the current status flag indicates that the site has been taken offline.
The available evidence does not disclose a targeted brand, specific phishing kit, or credential‑harvesting form, and there are no publicly shared URLs or payload samples linked to this domain. Consequently, the precise attack vector and victim profile remain uncertain. Defenders should continue to block grok15k.com at DNS and perimeter firewalls, monitor the associated IP address for any re‑use, and incorporate the domain into threat‑intel feeds. Ongoing vigilance is advised, especially for any future resolution of the domain or similar placeholders that may be re‑activated for phishing campaigns.
Охват данных12 recorded checks
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчетыIndependent lookups and source reports
PD-20260227-092E98 Recipient: abuse@namesilo.com Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.