Analysis indicates that the domain kronex.loan was registered on July 17 2026 through Ultahost, Inc. and is currently resolved to the IP address 188.114.97.3, which is hosted on Cloudflare’s network (authoritative name servers hera.ns.cloudflare.com and michael.ns.cloudflare.com). The domain is classified as a generic phishing site and is listed as high‑risk. It has been observed on one public security blocklist and is actively blocked by the PhishDestroy sink‑hole service.
VirusTotal scans show that 2 of 91 antivirus and URL‑reputation engines flag the domain as malicious, confirming that at least a minority of vendors have identified suspicious behavior. No additional public intelligence such as Safe Browsing, OTX, SSL certificate details, or HTTP response codes is available at this time, so the full payload and victim interaction profile remain unknown. Defenders should treat kronex.loan as a confirmed phishing infrastructure: add the domain and its resolving IP (188.114.97.3) to DNS and proxy blocklists, enforce outbound filtering to prevent connections, and monitor for any authentication attempts targeting the domain.
Continuous re‑scanning with VirusTotal and periodic checks of the Cloudflare name‑server records are recommended to detect any future changes to the hosting configuration. Given the recent registration date and active status, rapid containment is advised to mitigate potential credential‑stealing campaigns that may leverage this domain.