pepeedrop92[.]cat
“Domain Suspended”
Analysis of pepeedrop92.cat shows a newly registered domain (creation date 28 April 2026) that is actively serving a phishing infrastructure. The domain resolves to IP 81.88.48.71, an address allocated to Register.IT S.p.A. in Italy and hosted on nameservers dns1.nominalia.com and dns2.nominalia.com, both operated by the registrar Nominalia. The site presents a HTTP 302 redirect and returns the page title "Domain Suspended" under an SSL certificate issued by Sectigo Limited (Sectigo Public Server Authentication CA OV R36). Threat intelligence indicates the campaign targets cryptocurrency users, classified as a crypto‑related phishing attempt. The domain appears on three security blocklists and is currently blocked by PhishDestroy, MetaMask, and SEAL. Reputation scoring is extremely low, with a Gridinsoft trust score of 0 / 100. VirusTotal analysis records detections by 2 of 91 security vendors, and AlienVault OTX references the domain in a single threat pulse. The overall risk assessment is high and the status remains active. Defenders should block the domain at network perimeter, monitor DNS queries for the associated IP and nameservers, and incorporate the indicator set into endpoint and email filtering rules. Continuous re‑evaluation is advised, as additional detections may emerge as the campaign evolves.
Threat Response Pipeline
Public Blocklist Status
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive