Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@internet.bs.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
grok49k-cointelegraph[.]com
“Elon Musk Officially Launches GROK49K Presale”
grok49k-cointelegraph.com — Неперевірений. Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 1 alert; PhishDestroy score 93/100. Реєстратор: Internet Domain Servic….
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, grok49k-cointelegraph.com, is currently flagged as an active phishing infrastructure targeting cryptocurrency users. Analysis indicates the site presents itself as a token presale for an asset labeled GROK49K, with the page title explicitly stating 'Elon Musk Officially Launches GROK49K Presale.' While the domain name incorporates elements resembling a well-known cryptocurrency news outlet, no direct evidence confirms an official association with that brand or Elon Musk. The exact content and mechanics of the scam remain unconfirmed, though the presence of a 'Token Presale' phishing kit suggests an attempt to deceive users into transferring funds under false pretenses. Infrastructure analysis reveals the domain was registered on March 13, 2026, through Internet Domain Service BS Corp, and resolves to the IP address 192.142.10.5. It is hosted on a server running WordPress, MySQL, PHP, Vue.js, LiteSpeed, and jQuery, alongside Google Tag Manager and Google Analytics, which are commonly used for tracking user interactions. The domain is detected by 13 out of 95 security vendors on VirusTotal and appears in 23 threat intelligence pulses on AlienVault OTX, indicating widespread recognition as malicious. It is also blocked by at least two security systems, further corroborating its classification as a high-risk threat. The SSL certificate issued by Let's Encrypt provides encryption but does not validate the legitimacy of the site. Defenders should treat this domain as actively malicious, particularly in environments where cryptocurrency transactions occur. Network-level blocking of the domain and its resolving IP is recommended, along with monitoring for related infrastructure that may reuse the same hosting provider or registration patterns. Given the domain's recent creation and persistent activity, it is likely part of an ongoing campaign rather than an isolated incident. No evidence currently suggests this infrastructure has been taken down or abandoned.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | grok49k-cointelegraph.com |
phishing | Phishing Block |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 9 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
Progressive JavaScript framework for building user interfaces.
High-performance web server compatible with Apache configurations.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comWeb analytics service tracking website traffic and user behavior.
marketingplatform.google.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of grok49k-cointelegraph.com · checked Jul 12, 2026
Докази та зовнішні звіти
PD-20260313-F2912A Recipient: abuse@internet.bs Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога