Analysis of the domain komuricraft.com indicates that it is currently active and has been observed on a single security blocklist. The domain resolves to the IP address 188.114.96.3, which is hosted behind Cloudflare infrastructure as evidenced by the authoritative name servers kareem.ns.cloudflare.com and marlowe.ns.cloudflare.com. Registration records show the domain was created on June 21, 2026 and was purchased through Dynadot Inc, a registrar that is frequently used by threat actors for rapid provisioning of malicious sites.
The domain is listed as blocked by the PhishDestroy blocklist, confirming that at least one anti‑phishing feed has identified it as malicious. VirusTotal reports that the domain was scanned by 91 vendor engines, none of which have generated a detection at the time of analysis; this lack of detections does not imply the domain is benign and should be treated with caution. No additional intelligence such as page title, brand targeting, or specific phishing kit fingerprints has been released, leaving the exact content and attack vector of the site uncertain.
Defenders should continue to monitor DNS queries for komuricraft.com, enforce outbound filtering that blocks connections to the associated IP address, and ensure that any email or web gateway solutions reference up‑to‑date blocklists that include the domain. Because the domain is newly registered and already appears on a blocklist, it is advisable to add it to internal deny lists, employ URL reputation services, and consider sandbox analysis of any payloads that may be delivered from the site. Ongoing vigilance is recommended, as the threat actor may later deploy credential‑stealing pages or other malicious content targeting unsuspecting users.