kmspicodl[.]com
“Download KMSPico Activator | Official Site [FEB 2026] - KMSPico”
Зведення доказів
Analysis indicates that kmspicodl.com was registered on 11 March 2026 through Shinjiru Technology Sdn Bhd and immediately pointed to the Cloudflare network (ASN 13335). DNS resolution returns the address 188.114.96.3, which belongs to Cloudflare’s US edge infrastructure. The domain uses Cloudflare’s authoritative name servers june.ns.cloudflare.com and rommy.ns.cloudflare.com and serves an HTTPS certificate issued by Let’s Encrypt (E8 identifier). The only visible artefact is a page title reading “Download KMSPico Activator | Official Site [FEB 2026] - KMSPico”, which references the KMSPico tool commonly associated with illicit Microsoft product activation.
The threat profile lists the site as a brand‑impersonation and tech‑support scam targeting Microsoft users. Independent security services have flagged the domain; three of ninety‑four VirusTotal scanners raised detections, and the domain appears on blocklists operated by PhishDestroy, MetaMask, and SEAL. Current HTTP status is offline, suggesting the site has been taken down or is temporarily unavailable. Evidence does not reveal the actual content served, the presence of malicious payloads, or any observed victim traffic, leaving the exact delivery mechanism uncertain.
Defenders should continue to block kmspicodl.com at network perimeter, update DNS filtering rules, and monitor for any resurgence of the domain or similar aliases using the same Cloudflare edge IPs. Correlation of internal logs against the 188.114.96.3 address and the Cloudflare name servers can help identify any missed connections. Given the brand‑impersonation intent and existing detections, the domain should be treated as high‑risk until confirmed remediation.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
8 зовнішніх джерел під наглядом Збігів немає
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога