Güvenlik raporuna geç
⚠️
Suspicious Domain — Listed on PhishDestroy
Depolanan PhishDestroy tehdit listesi. VirusTotal analysis stored; no vendor detections were recorded at check time. Çok dikkatli olun — kimlik bilgilerini veya kişisel bilgileri girmeyin.
Etki alanı güvenliği ve tehdit istihbaratı

grok26k[.]com

grok26k.com için kimlik avı ve güvenlik kontrolü

“GROK26K Official Website Presale (up to 200% bonus)”

Tehdit kararı İşaretlendi 48/100 kanıt puanı
Kullanılabilirlik İçerik kullanılamıyor En son gözlemde içerik mevcut değildi
Risk sinyalleri
Depolanan PhishDestroy tehdit listesi Dolandırıcılık türü: Brand Impersonation
18.05.2026 26.05.2026'den beri kullanılamıyor Brand Impersonation 1 Report Sent 7d to unavailable CDN
Rapor özeti

grok26k.com — İçerik kullanılamıyor (HTTP 502). Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 0 detections (engine total unavailable); PhishDestroy score 48/100. Kayıt kuruluşu: Ultahost.

Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.

Evidence Analysis

Stored analysis · 18.05.2026 Ref 4B808AEF 48/100 FLAGGED

PhishDestroy identifies grok26k.com as an active credential theft phishing domain used to harvest user login details and sensitive information. The site remains under investigation but continues to operate with confirmed malicious intent. No specific brand impersonation has been confirmed at this stage of analysis.

This domain was flagged by 0 of 95 VirusTotal vendors as of the latest scan, indicating low detection despite its active threat status. grok26k.com is registered through Ultahost, Inc., resolves to IP 99.83.231.61, and holds a Let's Encrypt SSL certificate issued for web security obfuscation. The domain was created on May 17, 2026—a recent registration timeline suggesting opportunistic deployment. It has not yet appeared on major threat intelligence blocklists, and real-time trust scores remain uncompromised. However, the absence of detections should not be interpreted as safety, particularly given the active credential theft operation under investigation.

Authorities recommend immediate network and endpoint blocking of grok26k.com and IP 99.83.231.61. Organizations should audit outbound traffic to prevent data exfiltration and warn users against interacting with the domain. Deployments of browser-based security extensions that block known phishing vectors are strongly advised. Continuous monitoring via threat intelligence feeds for emerging blocks is essential. Administrators are urged to update firewall rules, DNS sinkholes, and email filtering systems to block all communications with the domain and associated infrastructure. Given the low VT detection rate, this domain represents a high-risk, high-impact threat vector requiring urgent containment action.

VirusTotal
VirusTotal
0 det.
URLScan
URLScan
TLS sertifikası
Let's Encrypt
Yaş
3 mo New
Gözlemlenen durum
İçerik kullanılamıyor 502
PhishDestroy
DestroyList
Listede
Reports Sent
1
Veri kapsamı12 recorded checks
VirusTotal checked — no detections recorded URLQuery rapor saklandı — ayrıntılı karar bekleniyor PhishStats checked — no match recorded OTX no community references CF Radarı scan completed URLScan capture saklanan rapor URLScan verdict Analiz tamamlandı DNS engellemeleri 14 kontrol edildi — engelleme yok TLS valid certificate, 88d WHOIS 3 mo old Ekran görüntüsü 2 captures · 2 sources Yönlendirme zinciri araştırılmadı

Tehdit Müdahale Pipeline

Keşif
Checks
Reports
Kullanılabilirlik
12/12
Sent Report Recorded
Stored sent-report record for registrar Ultahost, Inc., hosting provider, 3 abuse contacts
abuse@ultahost.comu-abuse@ultahost.comwebproxy@whoisprotection.domains
18.05.2026

Genel Engelleme Listesi Durumu

Kaydedilen görüntü

Sayfa başlığı
GROK26K Official Website Presale (up to 200% bonus)
TLS sertifikası
Valid transport encryption · Düzenleyen Let's Encrypt · valid for 88 days

Etki Alanı Analizi

Alan adı
URLScan Verdict Analiz tamamlandı score 0 report ↗
Sunucu / ASN Netlify · AS16509 Amazon.com, Inc.
IP Context Netlify shared edge origin IP hidden Edge-IP itibarı bu etki alanıyla ilişkilendirilmez.
IP adresi 99.83.231.61 CDN
Coğrafi konumUS Seattle, US
AS16509 · AWS Global Accelerator (GLOBAL)
Kaynak IP, bir CDN proxy'sinin arkasına gizlenir. Uç adresine ilişkin Ters IP sonuçları ilgisiz kiracılar içerir; Kaynağı bulmak için pasif DNS veya sertifika şeffaflığı verileri gerekir.
KayıtOluşturuldu 17.05.2026 (83d · New)
HTTP Durumu502 Error
İlk erişilemezliğe kadar geçen süre 7 days
Neyi ölçüyoruz Depolanan ilk kötüye kullanım raporundan içeriğin kullanılamadığına dair ilk gözleme kadar geçen süre. Bu, nedeni belirlemez.
Her raporun içeriği Saklanan giden rapor kayıtları, satıcı kararları, kayıt verileri, barındırma ayrıntıları, sınıflandırmalar veya ekran görüntüleri gibi o sırada mevcut olan kanıtlara referans verebilir. Bu sayfa, teslim edilen yükün, alındığının, onaylandığının veya alıcının yaptığı eylemin tam olarak ne olduğu konusunda bir sonuç çıkarmaz.
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
İlk Kez Tespit Edildi18.05.2026
IoC Extractionscanned 01.08.20260 wallet · 0 Telegram IoCs
Submitted URLhttp://grok26k.com/
Ad sunucularıart.ns.cloudflare.comivy.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 17.05.2026scanned 18.05.2026
TLS SAN Domainswww.grok26k.com
Case ID
ICANN OVERSIGHT

Akreditasyon ve RAA bağlamı

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Hiçbir şey otomatik olarak gönderilmez.
Teknolojiler · 7 identified
WordPress
CMS Blogs

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.

wordpress.org %100 güven
MySQL
Databases

MySQL is an open-source relational database management system.

mysql.com %100 güven
PHP
Programming languages

PHP is a general-purpose scripting language used for web development.

php.net %100 güven
Tidio
Live chat

Tidio is a customer communication product. It provides multi-channel support so users can communicate with customers on the go. Live chat, messenger, or email are all supported.

www.tidio.com %100 güven
Netlify
PaaS CDN

Netlify providers hosting and server-less backend services for web applications and static websites.

www.netlify.com %100 güven
jQuery
JavaScript libraries

jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.

jquery.com %100 güven
HSTS
Güvenlik

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

www.rfc-editor.org %100 güven
Detected via Cloudflare Radar · Wappalyzer engine
Bu Alan Adını Bildir Kanıt sunun ve başkalarını korumaya yardımcı olun

VirusTotal Analizi

0 detections recorded · vendor total unavailable
View on VT
Last analyzed
No VirusTotal engine marked the domain malicious in the stored analysis.
Site Performans Analizi

Google PageSpeed Insights — mobile performance audit of grok26k.com · checked May 18, 2026

61
Needs Work
Performance
FCP
4.36s
First Contentful Paint
LCP
12.61s
Largest Contentful Paint
CLS
0.029
Cumulative Layout Shift
TBT
86ms
Total Blocking Time
SI
6.17s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.

Europol
AB ülkeniz için resmi raporlama kanalını bulun
National police directory
Kurtarma dolandırıcılarına dikkat edin! Suçlular, araştırmacı, avukat veya kurtarma görevlisi gibi davranarak mağdurlarla tekrar iletişime geçebilir. Peşin ücret ödemeyin veya kimlik bilgilerinizi paylaşmayın. Geri ödeme dolandırıcılığı hakkında daha fazla bilgi edinin →

Yerel Yetkililere Bildirin

resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.

97 ülke rehberi
Yapay zeka destekli taslak — olay ayrıntıları yapay zeka sağlayıcısı tarafından işlenir Kendiniz inceleyin ve gönderin
Bu Raporu YerleştirRead-only HTML widget
HTML · IFRAME

Bu Raporu Yerleştir

Bu tehdit bilgisini web sitenizde veya blogunuzda paylaşın

embed.html
<iframe
  src="https://phishdestroy.io/tr/embed/domain/grok26k.com"
  title="PhishDestroy threat report for grok26k.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Çok İçten Bir Teşekkür Mektubu

Hicivli taslak oluşturucu

Alıcı
Ücret bağlamı

Hicivli taslak. Ücret rakamları tahminidir; bu alan adına kesin olarak atfedildikleri iddia edilmez.