MALICIOUS — CRITICAL
khampt[.]com
This domain, khampt.com, is flagged as a credential harvesting phishing site designed to deceive users into submitting sensitive authentication details.
- VirusTotal
- 6/94
- Blocklists
- No stored match
- Kullanılabilirlik
- İçerik kullanılamıyor · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
khampt.com — İçerik kullanılamıyor (HTTP 502). Dolandırıcılık türü: Credential Phishing. Kanıt özeti: VirusTotal 6/94 (alphaMountain.ai, BitDefender, Fortinet, G-Data, Gridinsoft); URLQuery 1 alert; PhishDestroy score 72/100. Kayıt kuruluşu: Spaceship.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
khampt.com: Credential Harvesting Phishing Site Confirmed
khampt.com identified as a credential harvesting phishing domain. Detected by 6/95 security engines, created November 19, 2025, targeting user authentication.
This domain, khampt.com, is flagged as a credential harvesting phishing site designed to deceive users into submitting sensitive authentication details. Analysis indicates the infrastructure is engineered to mimic legitimate login portals, likely targeting corporate or financial service credentials. The site employs evasion techniques such as Cloudflare protection to obscure its malicious intent and delay detection by security systems. Infrastructure analysis reveals multiple high-confidence indicators of compromise. The domain was registered on November 19, 2025, through Spaceship, Inc., a registrar frequently associated with short-lived phishing campaigns. It resolves to the IP address 172.67.137.19 and is detected by 6 out of 95 security vendors on VirusTotal, including explicit phishing classifications. The domain appears on one security blocklist and has been assigned a trust score of 0/100, further corroborating its malicious nature. Technologies detected include Cloudflare and HTTP/3, which are commonly exploited to mask hosting origins and accelerate malicious payload delivery. Users who visited khampt.com or interacted with its content should take immediate remediation steps. All credentials entered on the site must be considered compromised and reset across all platforms where identical or similar passwords were used. System scans using updated endpoint protection should be conducted to detect potential malware or browser-based persistence mechanisms. Network traffic logs should be reviewed for connections to 172.67.137.19 or related domains registered through Spaceship, Inc. Organizations should update their security policies to block this domain and its associated IP at the perimeter level to prevent further exposure.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı13 recorded checks
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | khampt.com |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Adli İstihbarat
Teknolojiler · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of khampt.com · checked Jun 26, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
PD-20260324-A4BDB3 Recipient: abuse@spaceship.com Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.