kast-app[.]app
“KAST Login – The global money app powered by stablecoins”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
This domain, kast-app.app, was registered on 12 March 2026 through NiceNIC International Group Co., Limited and resolves to 188.114.96.3, an address owned by Cloudflare (AS13335) in the United States. The site presented a page title of “KAST Login – The global money app powered by stablecoins,” indicating an attempt to harvest credentials for a stable‑coin‑related financial service. The TLS certificate is issued by Let’s Encrypt (E7) and the site employed common front‑end libraries such as jQuery, OWL Carousel, and jsDelivr, as well as Cloudflare features including HSTS, Browser Insights, and HTTP/3. HTTP responses return a 403 status code, and the domain is currently taken offline. Threat intelligence shows the domain appears on four public blocklists and has been flagged by four dedicated anti‑phishing services (PhishDestroy, MetaMask, ScamSniffer, SEAL).
VirusTotal analysis recorded detections by ten of ninety‑four scanning engines, reinforcing the malicious classification. The combination of a credential‑phishing lure, rapid registration, and use of reputable hosting infrastructure is consistent with a high‑risk phishing campaign targeting users of cryptocurrency or stable‑coin applications. Uncertainty remains regarding the exact payload delivered to victims, as the site is no longer reachable and no malware hashes have been published. No additional infrastructure such as command‑and‑control servers or secondary domains have been observed beyond the Cloudflare front‑end.
Defenders should immediately block kast-app.app at network perimeter and update endpoint allowlists to reject any connections to the associated IP address. Monitoring of new domains that resolve to the same Cloudflare IP range and that reference “KAST” or stable‑coin terminology is recommended.
Ağ Güvenliği İstihbaratı Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | kast-app.app/ |
malware | Detects file containing Telegram Bot API |
| YARAhub by abuse.ch | kast-app.app/favicon.ico |
malware | Detects file containing Telegram Bot API |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 kaynak · 10.08.2026 tarihinde eşitlendi
Tespit zaman çizelgesi
Kaydedilmiş gözlemler kronolojik sıradadır.
-
Erişilebilirlik
Erişilebilirlik: ilk kez unknown olarak gözlemlendi
993d00c35140 -
Erişilebilirlik
Erişilebilirlik: unknown → blocked
c683f3b8fd26 -
Erişilebilirlik
Erişilebilirlik: blocked → unknown
eddb9d5abfe8 -
Erişilebilirlik
Erişilebilirlik: unknown → blocked
bca17dfafbff -
Erişilebilirlik
Erişilebilirlik: blocked → unknown
7cebcfd4071c -
Erişilebilirlik
Erişilebilirlik: unknown → blocked
492242ffadd2 -
Erişilebilirlik
Erişilebilirlik: blocked → unknown
ca255b61650a -
Erişilebilirlik
Erişilebilirlik: unknown → blocked
879b0c302ce8 -
Erişilebilirlik
Erişilebilirlik: blocked → unknown
d8f7d37d7f95 -
Erişilebilirlik
Erişilebilirlik: unknown → blocked
ccd803e931a4
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler
7 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of kast-app.app · checked Mar 12, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin