kmspico-official[.]org
“KMSpico Download | Official Website KMS Activator【December 2024】”
Kanıt özeti
The domain kmspico-official.org is presently active and has been identified as a brand-impersonation site targeting Microsoft. Its registration on March 11, 2026 via Dynadot LLC, combined with the use of Cloudflare's DNS (koa.ns.cloudflare.com, millie.ns.cloudflare.com) and the IP address 104.21.14.199 (AS13335, United States), suggests a recent deployment of infrastructure that leverages reputable CDN services to obscure origin. The site returns HTTP 200 and presents the page title "KMSpico Download | Official Website KMS Activator【December 2024】," which aligns with the listed tech support scam classification.
Threat intelligence sources note that kmspico-official.org appears on three security blocklists and has been cited in 22 AlienVault OTX pulses. VirusTotal reports 16 of 94 security vendors flagging the domain, and Gridinsoft assigns a trust score of 0 out of 100, indicating a high likelihood of malicious activity. The domain is presently blocked by PhishDestroy, MetaMask, and SEAL, reinforcing its reputation as a malicious resource.
While the exact malicious payload or user‑interaction flow has not been publicly disclosed, the convergence of registration timing, blocklist presence, vendor detections, and the explicit "Tech Support Scam" label provides sufficient evidence for defensive action. Organizations should add kmspico-official.org to URL filtering and endpoint allow/deny lists, monitor DNS queries for the associated IP and nameservers, and consider additional telemetry collection to capture any attempted communications. Continuous re‑evaluation is advised as further analysis may reveal additional indicators of compromise.
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | kmspico-official.org |
malicious | Sinkholed |
| DNS4EU | kmspico-official.org |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
Tespit zaman çizelgesi
-
Alan adı durumu
Erişilebilir → Erişilemiyor
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of kmspico-official.org · checked Mar 24, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin