kast-app[.]app
“KAST Login – The global money app powered by stablecoins”
Збережене спостереження
Зафіксована відмінність заголовків
Зведення доказів
This domain, kast-app.app, was registered on 12 March 2026 through NiceNIC International Group Co., Limited and resolves to 188.114.96.3, an address owned by Cloudflare (AS13335) in the United States. The site presented a page title of “KAST Login – The global money app powered by stablecoins,” indicating an attempt to harvest credentials for a stable‑coin‑related financial service. The TLS certificate is issued by Let’s Encrypt (E7) and the site employed common front‑end libraries such as jQuery, OWL Carousel, and jsDelivr, as well as Cloudflare features including HSTS, Browser Insights, and HTTP/3. HTTP responses return a 403 status code, and the domain is currently taken offline. Threat intelligence shows the domain appears on four public blocklists and has been flagged by four dedicated anti‑phishing services (PhishDestroy, MetaMask, ScamSniffer, SEAL).
VirusTotal analysis recorded detections by ten of ninety‑four scanning engines, reinforcing the malicious classification. The combination of a credential‑phishing lure, rapid registration, and use of reputable hosting infrastructure is consistent with a high‑risk phishing campaign targeting users of cryptocurrency or stable‑coin applications. Uncertainty remains regarding the exact payload delivered to victims, as the site is no longer reachable and no malware hashes have been published. No additional infrastructure such as command‑and‑control servers or secondary domains have been observed beyond the Cloudflare front‑end.
Defenders should immediately block kast-app.app at network perimeter and update endpoint allowlists to reject any connections to the associated IP address. Monitoring of new domains that resolve to the same Cloudflare IP range and that reference “KAST” or stable‑coin terminology is recommended.
Data Coverage
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | kast-app.app/ |
malware | Detects file containing Telegram Bot API |
| YARAhub by abuse.ch | kast-app.app/favicon.ico |
malware | Detects file containing Telegram Bot API |
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 10.08.2026
7 зовнішніх джерел під наглядом Збігів немає
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології
Виявлено 7 технологій із високою впевненістю
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of kast-app.app · checked Mar 12, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога