kavrextilon[.]com
“Kavrextilon”
Evidence Summary
The domain kavrextilon.com was registered on 21 February 2026 through Metaregistrar BV and resolves to the IP address 188.114.97.3, which is hosted by Cloudflare (ASN 13335) in the United States. The authoritative name servers listed are lamar.ns.cloudflare.com and ximena.ns.cloudflare.com. No TLS certificate is presented, indicating that the site does not serve HTTPS traffic. When queried, the HTTP response returned the page title “Kavrextilon”, but the site has since been taken offline, preventing further content inspection.
Multiple security feeds flag the domain as a brand‑impersonation campaign targeting the brand “argent”. Google Safe Browsing classifies the URL as social engineering, and VirusTotal reports that 16 of 93 scanning engines have generated a detection. The domain also appears in a single AlienVault OTX pulse and is listed on three external blocklists, with active blocks from PhishDestroy, MetaMask, and SEAL. Gridinsoft assigns a trust score of 0 out of 100, reinforcing the low reputation.
The evidence confirms that kavrextilon.com is being used to masquerade as a legitimate service associated with argent, leveraging Cloudflare’s infrastructure to obscure its origin. Because the site is currently offline, the exact payload or credential‑harvesting mechanisms cannot be verified, and the content of the page beyond the title remains unknown. Defenders should continue to block the domain at network perimeter and endpoint layers, monitor DNS queries for the associated IP and name servers, and update threat intelligence repositories with the observed indicators. Ongoing observation of the IP address and any future re‑activation of the domain is recommended to capture additional artifacts should the campaign resume.
Submitted Evidence Snapshot
- Sent
- Ledger records
- 1
- Case ID
PD-20260119-DDBEC0- PDF artifact
- PDF evidence
Legal basis
Full evidence text
Acceptable Use Policy (AUP): The domain kavrextilon.com is engaged in phishing activities, which directly contravenes the AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The continued operation of this domain constitutes a violation of the TOS, which reserves the right to suspend or terminate services for any activities that breach legal standards or involve fraudulent practices.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and the fraudulent use of information obtained from such access.
Wire Fraud Statute (18 U.S.C. § 1343): This statute criminalizes schemes to defraud individuals or entities using electronic communications, which is applicable to phishing schemes.
Anti-Phishing Act of 2004: This law targets deceptive practices aimed at acquiring sensitive information through fraudulent means, aligning with the activities associated with this domain.
Regulatory Note: Failure to act on this report may expose your organization to liability under applicable laws and regulations. Immediate action is recommended to mitigate potential legal repercussions and uphold your commitment to maintaining a secure online environment.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 13, 2026
10 monitored external feeds No match
Detection timeline
-
Cloudflare Radar
Cloudflare Radar scan stored · Open scan
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive