europe-north[.]grtainewsone[.]info
europe-north.grtainewsone.info — 内容不可用. 品牌冒充:Investmentscam. 证据摘要: VirusTotal 1/91 (ESET); URLScan malicious verdict; PhishDestroy score 71/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain europe-north.grtainewsone.info is currently active and classified as a generic phishing infrastructure. VirusTotal reports that 1 of 91 security vendors has flagged the domain, indicating at least one detection but providing limited consensus. DNS resolution points to the IP address 104.21.61.61; no authoritative nameserver records are available (NS_NOT_FOUND). The combination of a single vendor flag, a public‑facing IP, and the high‑risk rating suggests the domain is being used for credential‑stealing or credential‑harvesting activities, even though the exact payload or target brand has not been disclosed. Uncertainty remains regarding the scale of the campaign, the hosting provider’s involvement, and any additional command‑and‑control endpoints that may be associated with the same IP. Defenders should immediately block traffic to and from europe-north.grtainewsone.info at perimeter firewalls and DNS resolvers, add the IP 104.21.61.61 to blacklists, and monitor outbound connections for similar resolution patterns. Continuous re‑evaluation of threat intelligence feeds for new detections is advised, as additional security vendors may flag the domain over time.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。