Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
kaias[.]org
“imToken Security | Wallet Risk Analysis Platform”
Resumo das evidências
PhishDestroy has flagged kaias.org as an operational fake-login page used in credential harvesting campaigns. The domain does not masquerade under a well-known brand but instead presents itself as a generic but plausible web portal, likely aiming to trick users into surrendering credentials under the guise of a routine authentication step. There is no evidence linking this site to a specific drainer kit at this time; however, its structure and rapid deployment indicate the use of a lightweight but effective phishing template designed for high-volume, low-effort compromise operations. kaias.org exhibits several transient threat indicators typical of opportunistic phishing infrastructure. VirusTotal currently shows zero detections across 95 engines as of the latest scan. Domain registration was processed via NameSilo, LLC, with creation occurring on January 31, 2026. The domain resolves to the IPv4 address 188.114.96.3 and is secured with a Google Trust Services SSL certificate, enhancing its appearance of legitimacy. At this stage, it remains unflagged in Google Safe Browsing (GSB) and has not been listed on major public blocklists, suggesting relatively recent deployment and low prior exposure across security platforms. The domain is classified as active under investigation with a current risk level labeled as under_investigation. Given the absence of detections, lack of GSB or blocklist coverage, and recent registration, the window of opportunity for exploitation may still be open. Immediate defensive actions include adding kaias.org and its resolving IP to internal blocklists, monitoring outbound DNS queries for resolutions to 188.114.96.3, and conducting user awareness outreach to discourage authentication attempts on unrelated domains. While the immediate threat is unconfirmed in scale, the combination of recent creation, zero detections, and active status warrants heightened vigilance until further behavioral or artifact analysis can be completed.
Instantâneo das evidências enviadas
- Enviado
- Registros do livro-razão
- 1
- ID do caso
PD-20260425-5D1690- Título da página capturada
- imToken Security | Wallet Risk Analysis Platform
- Artefato PDF
- Evidência em PDF
Base jurídica
Texto completo da evidência
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias
3 tecnologias identificadas com alta confiança
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of kaias.org · checked Apr 25, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo