grok79t[.]com
Перевірка домену grok79t.com на фішинг і безпеку
“GROK79T Official Website Presale (up to 200% bonus)”
grok79t.com — Останній відомий активний (HTTP 200). Тип шахрайства: Fake Airdrop. Зведення доказів: VirusTotal 6/91 (alphaMountain.ai, Bfore.Ai PreCrime, CRDF, Forcepoint ThreatSeeker, Gridinsoft); PhishDestroy score 80/100. Реєстратор: Internet Domain Servic….
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain grok79t.com was registered on April 21, 2026 through Internet Domain Service BS Corp and is currently marked as active with a high risk rating. The site returns HTTP 200 and presents the title “GROK79T Official Website Presale (up to 200% bonus)”, indicating a presale investment lure.
Infrastructure analysis shows the domain resolves to 99.83.231.61, an address located in the United States and served via AWS Global Accelerator. The site uses a Let’s Encrypt certificate (E8) and relies on Cloudflare nameservers nena.ns.cloudflare.com and theo.ns.cloudflare.com, a typical pattern for fast‑flux or evasive hosting.
Threat intelligence sources corroborate the malicious nature. AlienVault OTX lists the domain in one pulse, Gridinsoft assigns a trust score of 0 out of 100, and it appears on a single security blocklist. PhishDestroy actively blocks the domain, and VirusTotal reports one of ninety‑five scanners flagging it as malicious.
Observations remain limited; only a single detection pulse and a single vendor flag are available, leaving the full scope of the campaign uncertain. The page’s marketing language suggests a phishing campaign aimed at users seeking high‑return presale offers, but the specific victim demographics and any credential‑harvesting mechanisms have not been disclosed.
Defenders should add grok79t.com to DNS and URL filtering policies, enforce TLS inspection to capture the underlying HTTP content, and monitor for any additional domains that resolve to the same IP address or share the Cloudflare nameservers. Continuous re‑evaluation is advised as further indicators may emerge.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of grok79t.com · checked Apr 22, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога