Analysis of the domain test2.c3rberus.at indicates that it is currently active and classified as a generic phishing infrastructure. VirusTotal records show that 11 of 91 scanned security vendors have generated detections for the domain, suggesting a moderate level of malicious reputation. The domain is listed on a single external security blocklist and has been actively blocked by the PhishDestroy sinkhole service.
DNS resolution points to the IPv4 address 192.162.199.140, and the authoritative name servers are kallie.ns.cloudflare.com and trace.ns.cloudflare.com, confirming the use of Cloudflare’s DNS platform. No additional intelligence such as SSL certificate details, HTTP response codes, page title, or Safe Browsing verdicts are presently available, leaving the exact content and delivery mechanisms of the phishing page unverified. The limited visibility on blocklists and the relatively low vendor detection count mean the infrastructure may still be in early deployment or employing evasion techniques.
Defenders should add test2.c3rberus.at to inbound and outbound filtering rules, monitor DNS queries for the associated Cloudflare name servers, and enforce proxy or gateway inspection of traffic to the resolved IP address. Continuous re‑scanning with VirusTotal or similar multi‑engine services is recommended to capture any changes in detection coverage. Organizations should also consider sharing any observed payloads or URLs with threat‑intel sharing platforms to improve collective awareness.