Analysis of the domain content-x.kr shows a newly registered internet resource that is actively being used for a phishing campaign. The domain was created on July 28, 2026 and is registered through Gabia, Inc. It is hosted on the IP address 216.150.16.1 and uses the authoritative name servers ns1.vercel-dns.com and ns2.vercel-dns.com, indicating that the underlying web service is likely powered by Vercel’s hosting platform. The domain is currently listed on two public blocklists, PhishDestroy and SEAL, and both lists flag it as a phishing‑related resource.
VirusTotal records indicate that the domain was examined by 91 antivirus and URL‑reputation engines; none of the engines returned a detection at the time of scanning, which does not constitute a safety assurance. No additional data such as SSL certificate details, HTTP response codes, page title, or content snapshots are available in the intelligence set, leaving the exact appearance and payload of the site unknown. Given the recent creation date, the presence on dedicated phishing blocklists, and the resolution to a public IP address, defensive teams should treat content-x.kr as a high‑confidence phishing indicator.
Recommended actions include adding the domain to outbound and inbound URL filtering rules, monitoring DNS query logs for lookups to the associated nameservers, and extending threat‑intel feeds to capture any future changes in its status. Continuous re‑evaluation is advised, as further reconnaissance may reveal additional infrastructure or victim targeting patterns.