app-kindredlabs[.]xyz
app-kindredlabs.xyz — 未验证. 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 90/100. 注册商: Dynadot.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
app-kindredlabs.xyz is currently classified as a high‑risk generic phishing infrastructure. The domain was registered on April 29 2026 through Dynadot LLC and immediately pointed to Cloudflare’s network (172.67.154.204) using the authoritative name servers miles.ns.cloudflare.com and stephane.ns.cloudflare.com. The hosting IP resolves to a Cloudflare, Inc. location in Canada, and the TLS certificate is issued by Let’s Encrypt (E7), indicating a valid but easily obtainable certificate. Open Threat Exchange (OTX) lists the domain in a single pulse, and four independent security blocklists have added it to their watchlists. It is actively blocked by PhishDestroy, MetaMask, ScamSniffer, and SEAL. Gridinsoft’s trust score for the domain is 0 / 100, and VirusTotal reports that 5 of 95 scanned security vendors flag the domain as malicious. An HTTP GET to the domain returns a 403 Forbidden response, preventing direct observation of the landing page content. No additional infrastructure such as email servers, sub‑domains, or related URL paths have been publicly disclosed, leaving the exact phishing lure and target brand ambiguous. The combination of recent registration, use of Cloudflare’s edge network, low trust score, and multiple blocklist listings suggests a deliberate attempt to exploit the fast‑deployment capabilities of Cloudflare for phishing campaigns. The presence of a Let’s Encrypt certificate further indicates that the operators are leveraging free TLS to increase perceived legitimacy. Defenders should add app-kindredlabs.xyz to network‑level deny lists and configure DNS‑sinkholing to capture any future resolution attempts. Continuous monitoring of the associated IP address and the two Cloudflare name servers is advised, as the operators may shift to additional IPs or create sibling domains. Incident response teams should also query threat‑intel feeds for any emerging OTX pulses that reference the domain.
威胁响应 Pipeline
公共封禁名单状态
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。