preprod[.]grob[.]live
“Grob - Trade Cryptocurrency”
Kanıt özeti
The domain preprod.grob.live was a phishing site engaged in brand impersonation targeting Ethereum users. It posed as a cryptocurrency trading platform under the name 'Grob - Trade Cryptocurrency' to deceive victims into disclosing sensitive information or transferring funds. No drainer kit was identified, but the site was confirmed as a scam through brand impersonation tactics. As of the latest verification, preprod.grob.live has been taken offline.
Technical indicators for preprod.grob.live include detection by 2 of 95 VirusTotal security vendors, including SOCRadar. The domain was registered through PDR Ltd. d/b/a PublicDomainRegistry.com on July 29, 2025, and resolved to the IP address 188.114.96.3, hosted by Cloudflare, Inc. (AS13335) in the US. It appeared on one security blocklist, PhishDestroy, and had a Gridinsoft trust score of 0/100. No SSL certificate was available, and the site returned an HTTP 530 status. Nameservers were keaton.ns.cloudflare.com and laura.ns.cloudflare.com.
Victims of preprod.grob.live should immediately change any passwords or credentials entered on the site and enable two-factor authentication (2FA) on all related accounts. Monitor financial and cryptocurrency accounts for unauthorized transactions and report any fraudulent activity to the relevant platform. To report the phishing domain, submit it to Google Safe Browsing, PhishTank, or the impersonated brand’s security team (e.g., Ethereum’s abuse reporting channels). If cryptocurrency was transferred, contact the wallet provider or exchange for potential recovery options.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260103-9F6A9A- PDF belgesi
- PDF kanıtı
Kanıtın tam metni
Policy Violations: Explicit policy to immediately suspend domains used for phishing, 419 scams, identity fraud, malware distribution without prior notice
Applicable Laws: IT Act 2000 §§66C–66D (identity theft, cheating by personation), Indian Penal Code §420 / Bharatiya Nyaya Sanhita §318 (fraud)
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 10.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Registration: grob.live
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For the registrable domain grob.live behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin