kea47[.]at
Resumen de las pruebas
This domain, kea47.at, functions as a phishing gateway designed to intercept user credentials through deceptive authentication portals. Analysis indicates the site mimics login interfaces for financial or corporate services, leveraging Cloudflare infrastructure to obscure its true origin and evade detection. The domain’s structure and behavior align with credential-harvesting campaigns, where victims are redirected to fraudulent pages after interacting with seemingly legitimate prompts. Given its elevated risk classification, this domain poses a significant threat to individuals and organizations by facilitating unauthorized access to sensitive accounts. Infrastructure analysis reveals multiple technical indicators supporting its malicious classification. The domain resolves to IP address 104.21.59.161, a Cloudflare-hosted endpoint, and presents an SSL certificate issued by Google Trust Services, a common tactic to appear legitimate. VirusTotal reports 3 out of 95 security vendors flagging kea47.at as malicious, while Gridinsoft assigns a trust score of 0 out of 100. The domain was registered on February 21, 2026, through an undisclosed registrar, and is currently blocked by one security blocklist. Its page title, 'Just a moment...,' is consistent with Cloudflare’s interstitial pages, often exploited to delay or redirect users during phishing attempts. Users who visited kea47.at should immediately take corrective actions to mitigate potential compromise. Any credentials entered on this domain must be considered exposed and should be changed across all platforms where the same passwords were used. System scans using updated security tools are recommended to detect any residual malware or unauthorized access. Organizations should review logs for connections to 104.21.59.161 or related domains and implement additional authentication measures, such as multi-factor verification, to prevent further exploitation. Given the domain’s current offline status, users should remain vigilant for similar phishing attempts leveraging Cloudflare or other content delivery networks.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
VirusTotal
1 → 3
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of kea47.at · checked Jun 27, 2026
Análisis de la configuración del sitio
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.