kea47[.]at
Résumé des preuves
This domain, kea47.at, functions as a phishing gateway designed to intercept user credentials through deceptive authentication portals. Analysis indicates the site mimics login interfaces for financial or corporate services, leveraging Cloudflare infrastructure to obscure its true origin and evade detection. The domain’s structure and behavior align with credential-harvesting campaigns, where victims are redirected to fraudulent pages after interacting with seemingly legitimate prompts. Given its elevated risk classification, this domain poses a significant threat to individuals and organizations by facilitating unauthorized access to sensitive accounts. Infrastructure analysis reveals multiple technical indicators supporting its malicious classification. The domain resolves to IP address 104.21.59.161, a Cloudflare-hosted endpoint, and presents an SSL certificate issued by Google Trust Services, a common tactic to appear legitimate. VirusTotal reports 3 out of 95 security vendors flagging kea47.at as malicious, while Gridinsoft assigns a trust score of 0 out of 100. The domain was registered on February 21, 2026, through an undisclosed registrar, and is currently blocked by one security blocklist. Its page title, 'Just a moment...,' is consistent with Cloudflare’s interstitial pages, often exploited to delay or redirect users during phishing attempts. Users who visited kea47.at should immediately take corrective actions to mitigate potential compromise. Any credentials entered on this domain must be considered exposed and should be changed across all platforms where the same passwords were used. System scans using updated security tools are recommended to detect any residual malware or unauthorized access. Organizations should review logs for connections to 104.21.59.161 or related domains and implement additional authentication measures, such as multi-factor verification, to prevent further exploitation. Given the domain’s current offline status, users should remain vigilant for similar phishing attempts leveraging Cloudflare or other content delivery networks.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
VirusTotal
1 → 3
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of kea47.at · checked Jun 27, 2026
Analyse de la configuration du site
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif