Analysis of katanapromo.live indicates that the domain was registered on July 22 2026 through the corporate entity Fewmoretaps OU d/b/a Trustname.com. The authoritative name servers are dns1.p04.nsone.net through dns4.p04.nsone.net, and DNS resolution points to the single IPv4 address 35.157.26.135. The domain is currently classified as a generic phishing site and remains active as of the report date (July 30 2026). VirusTotal has processed the domain with 91 antivirus and URL‑reputation engines; none of the scanners have raised a detection, but the absence of a flag does not constitute evidence of benign intent.
The domain is already listed on one public security blocklist and is actively blocked by the PhishDestroy feed, demonstrating that at least one threat‑intelligence source has identified malicious use. No public Safe Browsing, Open Threat Exchange, or similar reputation data were observed, and there is no publicly available information on SSL certificates, HTTP response codes, page titles, or content signatures. Consequently, the full scope of the phishing campaign—such as target brands, lure techniques, or credential‑harvesting pages—remains unknown.
Defenders should immediately add 35.157.26.135 and the domain name katanapromo.live to outbound and inbound filtering rules, monitor DNS queries for the listed NS records, and enable continuous scanning with URL‑reputation services. Given the recent registration date and active blocklist status, ongoing telemetry collection is advised to detect any evolution of the infrastructure, including potential IP changes or additional hosting assets. Organizations are encouraged to treat any user‑initiated traffic to this domain as malicious until further forensic analysis confirms otherwise.