MALICIOUS — CRITICAL
blackcatpayments[.]com
Analysis of blackcatpayments.com shows it is an active generic phishing infrastructure observed on 14 July 2026.
- VirusTotal
- 1/91
- Blocklists
- 2 · MetaMask, SEAL
- Availability
- Content unavailable · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
Evidence Analysis
blackcatpayments.com: Generic Phishing Site
Analysis of blackcatpayments.com shows it is an active generic phishing infrastructure observed on 14 July 2026.
Analysis of blackcatpayments.com shows it is an active generic phishing infrastructure observed on 14 July 2026. The domain resolves to IP address 188.114.96.3 and is served over TLS with a Google Trust Services / WE1 certificate, indicating a valid HTTPS endpoint. Registration records list Hostinger Operations, UAB as the registrar, with the domain creation date of 11 July 2026. DNS is delegated to Cloudflare name servers bailey.ns.cloudflare.com and jaxson.ns.cloudflare.com. The site has been scanned by 91 VirusTotal vendors without any current detections; however, the lack of detections does not confirm safety. The threat is currently classified as generic phishing and remains under investigation. Uncertainty remains regarding the specific content hosted on the site, as no page‑level analysis is available. Defenders should consider adding the domain and its associated IP to blocklists, monitor outbound connections for traffic to the IP, and continue periodic re‑scans to detect any future malicious payloads.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Data coverage12 recorded checks
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | blackcatpayments.com |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External ReportsIndependent lookups and source reports
PD-20260714-20D390 Recipient: abuse-tracker@hostinger.com Victim safety and official reportingImmediate actions and verified reporting channels
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.