kmspicodl[.]com
“Download KMSPico Activator | Official Site [FEB 2026] - KMSPico”
Сводка доказательств
Analysis indicates that kmspicodl.com was registered on 11 March 2026 through Shinjiru Technology Sdn Bhd and immediately pointed to the Cloudflare network (ASN 13335). DNS resolution returns the address 188.114.96.3, which belongs to Cloudflare’s US edge infrastructure. The domain uses Cloudflare’s authoritative name servers june.ns.cloudflare.com and rommy.ns.cloudflare.com and serves an HTTPS certificate issued by Let’s Encrypt (E8 identifier). The only visible artefact is a page title reading “Download KMSPico Activator | Official Site [FEB 2026] - KMSPico”, which references the KMSPico tool commonly associated with illicit Microsoft product activation.
The threat profile lists the site as a brand‑impersonation and tech‑support scam targeting Microsoft users. Independent security services have flagged the domain; three of ninety‑four VirusTotal scanners raised detections, and the domain appears on blocklists operated by PhishDestroy, MetaMask, and SEAL. Current HTTP status is offline, suggesting the site has been taken down or is temporarily unavailable. Evidence does not reveal the actual content served, the presence of malicious payloads, or any observed victim traffic, leaving the exact delivery mechanism uncertain.
Defenders should continue to block kmspicodl.com at network perimeter, update DNS filtering rules, and monitor for any resurgence of the domain or similar aliases using the same Cloudflare edge IPs. Correlation of internal logs against the 188.114.96.3 address and the Cloudflare name servers can help identify any missed connections. Given the brand‑impersonation intent and existing detections, the domain should be treated as high‑risk until confirmed remediation.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
8 внешних источников под наблюдением Совпадений нет
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание