The domain kybers-wap.com was registered on July 11, 2026 through Realtime Register B.V. and resolves to the IPv4 address 154.198.48.55. DNS resolution is served by the shared name server set a.share-dns.com, a5.share-dns.com, b.share-dns.net, and b5.share-dns.net, indicating the use of a public DNS hosting platform. Threat intelligence aggregators have flagged the domain as malicious: three of ninety‑one VirusTotal scanners labeled it as suspicious, and it appears on three independent blocklists. The domain is actively blocked by the PhishDestroy, MetaMask, and SEAL filtering services, reinforcing the consensus that it is being used for phishing‑related activity.
Analysis of the available data reveals a clear infrastructure pattern: a newly created domain, rapid deployment to a shared DNS service, and immediate inclusion on multiple blocklists. No public SSL certificate details, HTTP response codes, or page title information have been disclosed, so the exact content served by the site remains unverified. The lack of additional telemetry limits attribution beyond the observed hosting and registration artifacts.
Defenders should treat kybers-wap.com as a high‑confidence phishing indicator. Recommended actions include adding the domain and its resolving IP address (154.198.48.55) to outbound and inbound deny lists, enforcing DNS sinkholing for the associated name servers, and monitoring for any new sub‑domains that resolve to the same IP range. Continuous re‑scanning with VirusTotal or similar multi‑engine services is advised to capture any evolution in the payload. Organizations employing web‑filtering solutions should ensure the domain is included in blocklists from PhishDestroy, MetaMask, and SEAL, and should audit existing email and credential‑capture controls for attempts targeting this domain.