kxeg[.]online
“KXEG”
Evidence Summary
Analysis of kxeg.online shows the domain was registered on 27 November 2025 through GoDaddy.com, LLC and is served by four AWS Route 53 nameservers (ns-1028.awsdns-00.org, ns-1748.awsdns-26.co.uk, ns-405.awsdns-50.com, ns-870.awsdns). DNS resolution points to the IPv4 address 52.222.236.50, which remains reachable as of the report date. The domain appears in a single AlienVault OTX pulse, indicating that it has already been referenced by external threat‑intelligence sources. VirusTotal has processed the domain with 91 vendor scans; none have reported a detection at the time of writing, but the lack of a positive result does not guarantee the absence of malicious payloads. The only confirmed indicator is the classification as a generic phishing site, which suggests the infrastructure is intended to harvest credentials or other sensitive data. No additional artifacts such as malware hashes, URLs, or page content have been disclosed, leaving the exact phishing template and target unknown. Defenders should add 52.222.236.50 and the domain kxeg.online to block lists or network‑level deny rules, monitor DNS queries for the listed nameservers, and consider sinkholing the address if feasible. Continuous re‑inspection of VirusTotal and OTX updates is recommended to capture any future detections or additional context.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
8 monitored external feeds No match
Detection timeline
-
VirusTotal
0 → 2
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
5 high-confidence technologies identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of kxeg.online · checked Jul 18, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive