Analysis of 3658katli5243.cc indicates an active generic phishing infrastructure. The domain was registered on June 23, 2026 through DYNADOT LLC and is served from the IP address 40.81.18.27. DNS resolution is delegated to ns1.dns.com and ns2.dns.com. Threat intelligence shows the site is listed on a single security blocklist; PhishDestroy currently blocks the domain, confirming its malicious intent.
VirusTotal scans report that 15 of 91 security vendors flag the domain as malicious, reinforcing the high‑risk assessment. No additional public reputation services or safe‑browsing checks are available in the supplied data. The limited detection footprint suggests the campaign may be in early stages or employing low‑profile hosting.
Defenders should add 40.81.18.27 and the domain name to outbound and inbound filtering rules, monitor DNS queries for the domain, and ensure that any email or web traffic matching the domain is quarantined or dropped. Continuous re‑evaluation is advised, as further detection signatures may appear in other blocklists or vendor feeds. Until more detailed payload or page‑content analysis is released, the precautionary stance remains to treat the domain as a confirmed phishing source.