grollo-ex.icu
Appeared in the .icu zone on Monday, August 31, 2026; by the end of that day the census found active website about crypto web3. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
Brand-new .icu domain hosting an anonymous 'Grollo' crypto→ruble exchanger whose entire flow is 'give us your Telegram, an operator will send you wallet details' — no company registration, licence, KYC or offsite verification, only a Telegram handoff to a human operator, the classic no-recourse crypto-exchange fraud shape; 'Telegram' and 'Bybit P2P' appear as contact/rate source, not as impersonated brands.
The site presents itself as 'Grollo', a crypto-to-fiat exchange service with its own branding and business model, not impersonating a specific organization. However, the sealed-room form architecture (password field posting to self, no offsite links, Telegram contact-collection pattern) combined with the .icu TLD and request for Telegram usernames is consistent with a cryptocurrency scam or exit-fraud scheme rather than a legitimate exchange.
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Monday, August 31, 2026

Same data as JSON: /api/zone/domain/grollo-ex.icu. This page is not indexed by search engines and does not link to the site it describes.