katanna[.]network
“katana”
Analysis of the domain katanna.network shows a high‑risk, generic phishing infrastructure that was taken offline as of the report date, July 24 2026. The domain was registered on March 22 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is hosted on Cloudflare’s network, resolving to IP 172.67.142.21 located in Canada. The site operates without a TLS certificate, despite being served via Cloudflare, and negotiates HTTP/3 connections. Service fingerprints reveal the presence of jQuery and Google Hosted Libraries, as well as Cloudflare Browser Insights, indicating a typical web‑stack used by many malicious sites.
The page title returned by the server is "katana," but no further content analysis is available. Reputation data shows that 11 of 94 VirusTotal scanners flagged the domain, and Gridinsoft assigns a trust score of 0 / 100. The domain appears on four distinct security blocklists and has been actively blocked by PhishDestroy, MetaMask, ScamSniffer, and SEAL. The identified scam type is a fake exchange, suggesting the site attempted to harvest credentials or monetary assets by impersonating a legitimate trading platform.
While the domain is currently offline, defenders should continue to enforce blocks on the associated IP address and the domain itself across DNS and web‑filtering solutions. Ongoing monitoring of the hosting provider’s IP range and the identified nameservers (elsa.ns.cloudflare.com, kirk.ns.cloudflare.com) is recommended to detect any re‑use of the infrastructure for future campaigns. Additional threat‑intel feeds should be consulted for any reappearance of the domain or related indicators, and incident response teams should treat any residual traffic as potentially malicious, given the confirmed high‑risk classification.
Network Security Intelligence Registrar context
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-24 02:44:03 UTC
Technologies · 5 identified
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of katanna.network · checked Mar 21, 2026
Evidence & External Reports
PD-20260321-F3B9B4 Recipient: abuse@nicenic.net, compliance@icann.org Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive