SUSPICIOUS — FLAGGED
grok26k[.]com
PhishDestroy identifies grok26k.com as an active credential theft phishing domain used to harvest user login details and sensitive information.
- VirusTotal
- 0 detections
- Blocklists
- No stored match
- Доступність
- Контент недоступний · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
grok26k.com — Контент недоступний (HTTP 502). Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 0 detections (engine total unavailable); PhishDestroy score 48/100. Реєстратор: Ultahost.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
PhishDestroy identifies grok26k.com as an active credential theft phishing domain used to harvest user login details and sensitive information. The site remains under investigation but continues to operate with confirmed malicious intent. No specific brand impersonation has been confirmed at this stage of analysis.
This domain was flagged by 0 of 95 VirusTotal vendors as of the latest scan, indicating low detection despite its active threat status. grok26k.com is registered through Ultahost, Inc., resolves to IP 99.83.231.61, and holds a Let's Encrypt SSL certificate issued for web security obfuscation. The domain was created on May 17, 2026—a recent registration timeline suggesting opportunistic deployment. It has not yet appeared on major threat intelligence blocklists, and real-time trust scores remain uncompromised. However, the absence of detections should not be interpreted as safety, particularly given the active credential theft operation under investigation.
Authorities recommend immediate network and endpoint blocking of grok26k.com and IP 99.83.231.61. Organizations should audit outbound traffic to prevent data exfiltration and warn users against interacting with the domain. Deployments of browser-based security extensions that block known phishing vectors are strongly advised. Continuous monitoring via threat intelligence feeds for emerging blocks is essential. Administrators are urged to update firewall rules, DNS sinkholes, and email filtering systems to block all communications with the domain and associated infrastructure. Given the low VT detection rate, this domain represents a high-risk, high-impact threat vector requiring urgent containment action.
Обсяг даних12 recorded checks
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 7 identified
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
wordpress.org 100% впевненостіTidio is a customer communication product. It provides multi-channel support so users can communicate with customers on the go. Live chat, messenger, or email are all supported.
www.tidio.com 100% впевненостіNetlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 100% впевненостіjQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of grok26k.com · checked May 18, 2026
Докази та зовнішні звітиIndependent lookups and source reports
PD-20260518-8F7B3D Recipient: abuse@ultahost.com Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.