Analysis of katana24.biz shows a newly registered domain (creation date July 24, 2026) that is currently active and resolves to the IP address 104.21.26.108. The registrar listed is NICENIC INTERNATIONAL GROUP CO., LIMITED and the authoritative name servers are brady.ns.cloudflare.com and sara.ns.cloudflare.com, indicating the use of Cloudflare’s DNS infrastructure. VirusTotal records indicate the domain has been scanned by 91 security vendors; none of the scanners reported a detection, but the absence of a flag does not constitute a safety assurance. The domain is listed on a single security blocklist and has been explicitly blocked by the PhishDestroy service, suggesting that at least one threat intelligence feed has identified malicious activity associated with the host.
No public SSL certificate details, HTTP response codes, or page title information are presently available, limiting the ability to assess the content served by the site. Consequently, the exact phishing lure, targeted brand, or credential‑harvesting mechanism remains uncertain. Defenders should consider proactively blocking traffic to katana24.biz at perimeter firewalls and DNS filtering points, especially given its recent creation and association with a known blocklist. Ongoing monitoring of the IP address 104.21.26.108 for anomalous traffic patterns is recommended, as Cloudflare‑hosted IPs can serve multiple unrelated domains.
Continuous re‑scanning with multi‑vendor sandboxes is advised to capture any future payloads or changes in behavior. Organizations employing threat‑intel platforms should ingest the domain’s metadata—registrar, nameservers, creation date, and blocklist status—into their correlation engines to improve detection of related campaigns. Until further forensic evidence emerges, the domain should be treated as a potential phishing vector and mitigated accordingly.