MALICIOUS — CRITICAL
Verifica phishing e sicurezza per khampt.com
khampt[.]
This domain, khampt.com, is flagged as a credential harvesting phishing site designed to deceive users into submitting sensitive authentication details.
- VirusTotal
- 6/94
- Blocklists
- No stored match
- Disponibilità
- Contenuto non disponibile · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
khampt.com — Contenuto non disponibile (HTTP 502). Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 6/94 (alphaMountain.ai, BitDefender, Fortinet, G-Data, Gridinsoft); URLQuery 1 alert; PhishDestroy score 72/100. Registrar: Spaceship.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
This domain, khampt.com, is flagged as a credential harvesting phishing site designed to deceive users into submitting sensitive authentication details. Analysis indicates the infrastructure is engineered to mimic legitimate login portals, likely targeting corporate or financial service credentials. The site employs evasion techniques such as Cloudflare protection to obscure its malicious intent and delay detection by security systems. Infrastructure analysis reveals multiple high-confidence indicators of compromise. The domain was registered on November 19, 2025, through Spaceship, Inc., a registrar frequently associated with short-lived phishing campaigns. It resolves to the IP address 172.67.137.19 and is detected by 6 out of 95 security vendors on VirusTotal, including explicit phishing classifications. The domain appears on one security blocklist and has been assigned a trust score of 0/100, further corroborating its malicious nature. Technologies detected include Cloudflare and HTTP/3, which are commonly exploited to mask hosting origins and accelerate malicious payload delivery. Users who visited khampt.com or interacted with its content should take immediate remediation steps. All credentials entered on the site must be considered compromised and reset across all platforms where identical or similar passwords were used. System scans using updated endpoint protection should be conducted to detect potential malware or browser-based persistence mechanisms. Network traffic logs should be reviewed for connections to 172.67.137.19 or related domains registered through Spaceship, Inc. Organizations should update their security policies to block this domain and its associated IP at the perimeter level to prevent further exposure.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Copertura dei dati13 recorded checks
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | khampt.com |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Informazioni forensi
Tecnologie · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of khampt.com · checked Jun 26, 2026
Dati e relazioni esterneIndependent lookups and source reports
PD-20260324-A4BDB3 Recipient: abuse@spaceship.com Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.