Analysis of catecoin.digital indicates that the domain was registered on July 28, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is currently resolved to the Cloudflare‑hosted address 104.21.14.171. The authoritative name servers, laila.ns.cloudflare.com and ruben.ns.cloudflare.com, confirm that the site is using Cloudflare’s DNS and edge services, a pattern frequently observed in phishing infrastructure to conceal origin. The domain appears on a single external blocklist and has been actively blocked by the PhishDestroy service, reflecting that at least one threat‑intelligence feed has categorized it as malicious. VirusTotal reports that the domain has been scanned by 91 antivirus and URL‑reputation engines; none of the engines returned a positive detection at the time of scanning, which does not constitute evidence of benign intent but rather indicates that the payload or page content has not yet been captured by automated signatures. Publicly observable indicators are limited.
No SSL certificate details, HTTP response codes, or page‑title information are presently disclosed, and no Safe Browsing, OTX, or additional blocklist entries are referenced in the available intelligence. Consequently, the precise content hosted on catecoin.digital remains unknown, and the specific phishing lure (e.g., credential‑harvesting form, malicious download) cannot be confirmed. The classification as “generic phishing” derives from the threat tag supplied, but the lack of visible branding or targeted service prevents finer attribution. Defenders should consider immediate containment actions. Adding catecoin.digital to DNS‑based deny lists and firewall block rules will prevent client‑side resolution.
Because the domain is served through Cloudflare, leveraging Cloudflare’s own security controls (e.g., rate‑limiting, IP reputation blocks) may disrupt the malicious traffic without affecting legitimate services. Continuous monitoring of the IP address 104.21.14.