register-kta[.]xyz
register-kta.xyz — Errore del server (HTTP 502). Riepilogo delle prove: VirusTotal 5/93 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet, SOCRadar); Spamhaus DBL_SPAM; PhishDestroy score 65/100. Registrar: NiceNIC.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Analysis on July 24, 2026 assesses the domain register-kta.xyz, which was created on February 21, 2026 and is currently listed as offline. The domain resolves to the IP address 188.114.96.3, an address owned by Cloudflare, Inc. (AS13335) and located in the United States. DNS resolution uses the Cloudflare nameservers keyla.ns.cloudflare.com and mark.ns.cloudflare.com, indicating that the infrastructure is fully hosted behind Cloudflare's edge network. The TLS certificate presented is issued by Google Trust Services under the WE1 designation, confirming that HTTPS connections are terminated with a valid certificate from a recognized public CA.
VirusTotal reports five detections out of ninety-three scanning engines, and the domain is blocked by the PhishDestroy feed as well as an additional security blocklist, giving it a total of one external blocklist entry. Automated page analysis returns the title “Just a moment…”, and the page is identified as employing Cloudflare Browser Insights, Cloudflare services, and HTTP/3. No further content has been captured, and the specific phishing vector or targeted brand has not been disclosed in the available intelligence. The observable indicators—IP address, nameserver set, SSL certificate issuer, detection count, and blocklist presence—provide sufficient context for defensive controls.
Organizations should add 188.114.96.3 and register-kta.xyz to URL filtering and DNS sinkhole policies, and monitor Cloudflare-associated traffic for similar patterns. Because the site is offline, active probing is limited, but the historical presence on blocklists warrants continued observation in case the domain is re-activated or reused. At present, the primary uncertainty concerns the exact content of the phishing page and any credential-harvesting mechanisms that may have been employed before takedown.
Informazioni sulla sicurezza di rete Registrar context
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-11 03:47:50 UTC
Tecnologie · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisi di VirusTotal
Prove archiviate
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of register-kta.xyz · checked Apr 11, 2026
Dati e relazioni esterne
PD-20260214-7C6CBE Recipient: abuse@nicenic.net Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo