The domain k82o.top was registered on July 17, 2026 through NameMart Pte. Ltd. and currently resolves to the IPv4 address 154.39.104.130. Its authoritative name servers are ns1.1111343.com, ns2.1111343.com, ns3.1111343.com, and ns4.1111343.com, indicating the use of a single hosting provider for DNS resolution. VirusTotal has recorded 13 detections out of 91 scanned security vendors, reflecting a moderate consensus among AV engines that the domain is malicious. Independent phishing‑specific blocklists, including PhishDestroy and OpenPhish, have already listed the domain, and it appears on two additional security blocklists, reinforcing its classification as a high‑risk phishing infrastructure.
The domain remains active as of the report date (August 01, 2026) and no public evidence of takedown or remediation has been observed. Analysis of the available telemetry shows no publicly disclosed SSL certificate details, HTTP response codes, or page titles, meaning the content served by the site has not yet been captured or shared in open‑source intelligence feeds. Consequently, the exact phishing lure, targeted brand, or credential collection mechanism cannot be confirmed at this time.
Defenders should treat k82o.top as a live credential‑harvesting platform and block network traffic to the associated IP address (154.39.104.130) and its name servers. Security solutions that ingest blocklist feeds should ensure the domain is added to denylists, and endpoint detection and response tools should monitor for any attempted connections from internal hosts to this domain. Continuous monitoring of VirusTotal and other reputation services is recommended to capture any changes in detection scores or new analytical reports that could reveal the specific brand being spoofed or additional malicious payloads hosted on the same infrastructure.