project-grok[.]de
project-grok.de — 内容不可用 (HTTP 502). 品牌冒充:Discord; 诈骗类型:Crypto Drainer. 证据摘要: VirusTotal 3/94 (Gridinsoft, Seclookup, SOCRadar); PhishDestroy score 65/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies www.project-grok.de as hosting a generic cryptocurrency drainer, a malicious script designed to siphon digital assets from victims’ wallets upon interaction. This domain does not impersonate a specific brand but instead leverages a generic cryptocurrency-related facade to deceive users. The site appears to deploy a crypto drainer kit, likely targeting users through social engineering or phishing campaigns that advertise a false utility, reward, or service related to digital currencies. The absence of impersonation branding suggests a more opportunistic approach, relying on broad thematic lures rather than high-profile brand imitation. This domain resolves to IP address 217.160.0.242 and is currently associated with a Sectigo Limited SSL certificate, indicating an attempt to appear legitimate. As of the latest analysis, the domain shows 0 detections out of 95 on VirusTotal, remaining undetected by major antivirus engines. The domain was registered with an unknown registrar and the creation date has not been publicly disclosed. Google Safe Browsing (GSB) status is currently marked as 'under investigation,' and no known blocklist entries have been recorded. These technical indicators, especially the zero detections despite active hosting, suggest a relatively new or stealthily configured payload deployment mechanism. Current status remains active, with the domain actively serving content and likely propagating through targeted phishing vectors. PhishDestroy has flagged this domain under investigation due to its deployment of a crypto drainer and the absence of immediate detection by security vendors. Immediate action is recommended for users who may have interacted with this domain to revoke any connected wallet permissions and scan devices for malware. The remaining risk is assessed as medium-high given the active deployment of drainer scripts and low current detection rates, indicating potential for wider compromise. Users are urged to verify any unsolicited links or offers related to cryptocurrency using PhishDestroy’s verification tools or trusted security platforms before engagement.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of project-grok.de · checked Apr 7, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。