The domain pgroup.ro is currently flagged as a high‑risk, active generic phishing site. Registration data shows the domain was created on October 14, 2004 and is held through ICI – Registrar. Its authoritative name servers are ns1.mxserver.ro, ns2.mxserver.ro, ns3.mxserver.ro, and ns4.mxserver.ro, all pointing to the same hosting provider. DNS resolution maps the domain to the IP address 89.44.139.129, which remains online as of the report date, July 29, 2026.
VirusTotal scans have identified two detections out of ninety‑one security vendors, indicating that at least a small subset of scanners recognize malicious characteristics associated with the domain. The domain appears on one public blocklist, specifically PhishDestroy, confirming that it has been reported and actively blocked by external threat‑intelligence feeds. No additional intelligence such as page title, SSL certificate details, or HTTP response codes is available, leaving the exact content and lure technique of the site unverified.
Analysts should treat the domain as a confirmed phishing vector based on the existing detections and blocklist entry, and incorporate it into network and endpoint filtering policies. Continuous monitoring of the IP address and name server activity is advised, as changes in hosting or infrastructure could signal further campaign development. Defenders are recommended to update threat‑intel platforms with the domain indicator, enforce URL filtering to block any access attempts, and consider broader ISP‑level blocks if similar domains emerge from the same hosting environment.