# lgi-kkw.org — SUSPICIOUS > lgi-kkw.org is a new fake login portal under investigation for phishing. Resolves to 188.114.97.3 and has 0/95 VirusTotal detections. ## Summary PhishDestroy identifies lgi-kkw.org as an active fake login portal currently under phishing investigation. The domain poses a credible threat due to its recent creation and hosting infrastructure associated with deceptive authentication pages. Users are advised to exercise extreme caution when encountering this domain, as it may be used to harvest login credentials through spoofed interfaces. This domain was flagged by PhishDestroy on seed a1cfb6 and exhibits multiple red flags: it resolves to IP 188.114.97.3, carries a Google Trust Services SSL certificate, and remains undetected by VirusTotal with 0/95 security engines flagging it. The domain was registered on January 22, 2026, through TUCOWS.COM, CO., a registrar known for bulk domain processing that may facilitate anonymity in malicious registrations. Despite the SSL certificate, the domain’s age of less than 24 hours and zero detections indicate a high likelihood of being a newly activated phishing resource. The absence of detections suggests delayed recognition by threat intelligence networks, creating a critical window for exploitation. Mitigation against this specific threat requires immediate action: users should avoid interacting with lgi-kkw.org entirely, especially any login prompts or credential requests. Organizations should block the domain at DNS and firewall levels and inspect outbound traffic for connections to 188.114.97.3. Since the domain is not yet flagged by most security vendors, proactive threat hunting and user awareness training are essential to prevent credential theft. Report any suspicious use of this domain to your IT security team or through PhishDestroy’s submission portal using seed a1cfb6 for cross-validation. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-01-22 06:52:43 - Registrar: TUCOWS.COM, CO. - IP: 188.114.97.3 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/0b084250-7cde-4491-937e-e35a13202c96 - PhishDestroy: https://phishdestroy.io/domain/lgi-kkw.org/ - LLM endpoint: https://phishdestroy.io/domain/lgi-kkw.org/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/lgi-kkw.org/ Last updated: 2026-03-23