Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is intl-abuse@list.alibaba-inc.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
catlcloud[.]metakarat[.]vip
“Masuk CATL”
catlcloud.metakarat.vip — Неперевірений. Уособлення бренду: ["whatsapp"]; Тип шахрайства: Fake Exchange. Зведення доказів: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, CRDF, Gridinsoft, LevelBlue); PhishDestroy score 65/100. Реєстратор: Dominet (HK).
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, catlcloud.metakarat.vip, operates as a credential harvesting phishing site specifically designed to mimic Contemporary Amperex Technology Co., Limited (CATL) login interfaces. The page title 'Masuk CATL' suggests targeting of Indonesian-speaking users, likely aiming to collect enterprise credentials for subsequent unauthorized access to corporate systems or supply chain compromise. Analysis of the infrastructure indicates a deliberate attempt to impersonate legitimate cloud services associated with CATL, a critical component in global battery manufacturing and energy storage sectors. Technical indicators confirm the malicious nature of this domain. VirusTotal reports 6 out of 95 security vendors flagging catlcloud.metakarat.vip as malicious, while Gridinsoft assigns a trust score of 0/100. The domain was registered on March 27, 2026, through Dominet (HK) Limited, a registrar frequently associated with high-risk domains. Infrastructure analysis reveals resolution to IP address 163.181.214.143, and the domain appears on at least one security blocklist, with PhishDestroy currently blocking access. The creation date discrepancy (2026) suggests potential WHOIS manipulation or future-dated registration to evade immediate detection. Users who accessed catlcloud.metakarat.vip should assume credential compromise and take immediate remediation steps. All passwords entered on this domain must be reset from a clean device, prioritizing accounts with elevated privileges or access to sensitive systems. Enable multi-factor authentication (MFA) using app-based or hardware tokens, avoiding SMS-based methods. Monitor associated accounts for unauthorized access attempts, particularly those linked to enterprise resource planning (ERP) systems, supply chain management platforms, or financial portals. Organizations should review network logs for connections to 163.181.214.143 and implement domain-wide password resets if internal traffic to this IP is detected. Report the incident to relevant computer emergency response teams (CERTs) or sector-specific information sharing and analysis centers (ISACs) for broader threat intelligence dissemination.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: metakarat.vip
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain metakarat.vip behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of catlcloud.metakarat.vip · checked Jun 26, 2026
Докази та зовнішні звіти
PD-20260327-71B271 Recipient: intl-abuse@list.alibaba-inc.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога