The domain kunststeinviertel.de is currently listed as active malicious infrastructure targeting victims through a generic phishing campaign. Threat intelligence indicates that the domain appears on a single security blocklist, suggesting limited but confirmed detection by at least one reputable source. The authoritative name servers for the zone are cosmos.dns-parking.com and nova.dns-parking.com, which are commonly associated with domain parking services rather than legitimate business operations. DNS resolution points to the IPv4 address 9.205.104.141; no additional hostnames or reverse DNS entries have been linked to this IP in public repositories.
VirusTotal analysis shows that one out of ninety‑one scanned security vendors flagged the domain, providing a modest but non‑trivial detection signal. Independent monitoring by PhishDestroy has also blocked the domain, reinforcing the notion that it is being used for phishing purposes. No public SSL certificate data, HTTP status codes, or page title information are available, and the registrar details have not been disclosed in the supplied dataset. Consequently, defenders should treat kunststeinviertel.de as high‑risk and incorporate its IP address and domain name into outbound and inbound filtering rules.
Continuous monitoring of blocklist updates, additional VirusTotal scans, and passive DNS feeds is recommended to capture any changes in hosting, content, or detection posture. Organizations that employ automated web‑reputation services should ensure that the domain is flagged and that any user‑initiated connections to it are blocked or warned. The evidence set, identified by seed d96560, underscores the need for proactive defensive measures despite the relatively low detection count.