granddominiontrust[.]org
“Home - Grand Dominion Trust”
granddominiontrust.org — İçerik kullanılamıyor. Marka kimliğine bürünme: ["foundation"]; Dolandırıcılık türü: Investment Scam. Kanıt özeti: VirusTotal 14/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 2 alerts; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Kayıt kuruluşu: Ultahost.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Analysis conducted on July 23, 2026 identifies the domain granddominiontrust.org as an inactive infrastructure associated with an investment‑type phishing campaign. The domain was registered on February 28, 2026 through Ultahost, Inc. and is hosted on a server located in Canada (Tor‑exit node indicated by “Tzulo‑TOR”) that resolves to IP address 198.54.132.28. The authoritative nameservers ns1‑ns4.ultahost.com resolve to the same provider, confirming the registrar’s hosting environment. TLS is supplied by a Let’s Encrypt R13 certificate, indicating that HTTPS was available while the site was operational.
Automated scanning by VirusTotal recorded 14 detections out of 94 security vendors, and the domain appears on a single external blocklist, confirming that at least some security products have flagged the site. Gridinsoft assigned a trust score of 0 out of 100, reflecting a high confidence of malicious intent. The page title retrieved during the brief live check read “Home - Grand Dominion Trust,” matching the declared scam type of an investment fraud. Detected web technologies include PHP, Tailwind CSS, LiteSpeed, Alpine.js, Smartsupp, jsDelivr, and HTTP/3, all of which are commonly leveraged in phishing kits to render dynamic content and track visitors.
The domain is currently listed as offline by the monitoring service, and PhishDestroy has added it to its blocklist. Uncertainty remains regarding the specific payload delivered to victims, as no login forms or credential‑capture pages have been captured. Defenders should continue to block the IP 198.54.132.28 and the domain granddominiontrust.org at DNS and proxy layers, monitor for any re‑registration attempts, and update intrusion detection signatures to include the observed technology stack and the Let’s Encrypt certificate fingerprint. Ongoing observation of related subdomains and any resurgence of the hosting provider’s IP range is recommended.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Adli İstihbarat
Teknolojiler · 7 identified
Server-side scripting language designed for web development.
Utility-first CSS framework for rapid custom UI development.
High-performance web server compatible with Apache configurations.
Lightweight JavaScript framework for composing behavior directly in markup.
Live chat and visitor recording tool for customer support.
Free public CDN for open-source projects, serving files from npm and GitHub.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of granddominiontrust.org · checked Mar 18, 2026
Kanıtlar ve Dış Raporlar
PD-20260318-02D8CF Recipient: u-abuse@ultahost.com Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin