Critical risk detected
Malicious redirector domain used for command-and-control and phishing distribution, flagged by threat intelligence with high confidence. Our security stack flagged multiple threat indicators on this website. Don't enter personal information, deposit money, or download files.
Is kelvora.cfd legit or a scam?
Malicious redirector domain used for command-and-control and phishing distribution, flagged by threat intelligence with high confidence.
These checks passed — but they don't clear the site. A clean antivirus result, valid SSL, and a calm server only mean it isn't hosting malware; they say nothing about whether the business is real. This verdict is based on the site's conduct and content, not a malware detection.
Analysis Summary
MT Intelligence
Our threat-intelligence layer and Fortinet both identify kelvora.cfd as malicious infrastructure. The domain was registered 110 days ago with privacy protection enabled, masking the operator's identity. The page itself is a bare redirector with the title 'Redirecting...' and no contact information, business registration, or legitimate content — a classic pattern for phishing and malware distribution. Threat reports place it in a malware network with 95% confidence and a medium-risk signal score. The combination of recent registration, hidden ownership, redirector behavior, and explicit malicious-infrastructure classification makes this a high-confidence threat.
Website Preview
Automated page render — captured in a safe sandbox. What an ordinary visitor would see when loading the site.
Web Research Findings
Our live research agent queries scam-report databases, consumer-review sites, news coverage, and general web search for kelvora.cfd, then cross-checks business-registration records and look-alike domain patterns. Everything below is pulled from what it actually found.
- Domain registered approximately 110 days ago (WHOIS shows 2026-02-18); very new with hidden owner identity via paid privacy service.
- Listed on SOCRadar as malicious domain for C2/phishing/malware distribution with 95% confidence and 68/100 signal score; first seen Jun 6, 2026 in Maltrail IOC feed (CIRCL OSINT).
- Scamadviser reports Trust Score 0 (average), notes recent registration, hidden WHOIS, few visitors, and same registrar used by spammers/scammers; positive on valid SSL and DNSFilter safe.
- Page title "Redirecting..." with empty description suggests possible redirector behavior, consistent with threat intel for phishing/malware distribution.
- No user complaints, reviews, or Reddit mentions found; no business entity tied to the domain.
- No evidence of impersonating any major brand (no detected scam families or brand references).
Threat-intelligence databases flag kelvora.cfd as malicious infrastructure with 95% confidence, linked to a malware network and first observed in IOC feeds on June 6, 2026. The domain carries no business registration, no consumer reviews, and no legitimate online presence. Independent trust aggregators assign it a low score (40/100) and note the recent registration, hidden WHOIS, and association with a registrar commonly used in spam and scam operations.
Antivirus Engines
Security Scans
Checked against the major public blocklists used by browsers and security tools — no hits.
Contact Verification
We fetched the page and looked for real-world contact details. Legitimate businesses almost always publish an email on their own domain, a phone number, and a postal address. Scam shops usually don't.
- No contact email found anywhere on the page.
- No phone number listed on the page.
- No postal address visible on the page.
Domain & Encryption
Redirect Chain
- 1301http://kelvora.cfd/
- 2520https://kelvora.cfd/
Server Reputation
Scam-Type Likelihood
2 scam-type patterns detected
2 of 13 categories showed signals
We check every URL against 13 distinct scam categories so the verdict tells you not just how risky the page is, but what kind of risk it carries. Each meter pulls from page signals, web reports, our AI analyst, vision, and the scam-network cluster — not from raw AV labels.
- AI analyst tagged this as malware / drive-by / cracked app.
- AI analyst tagged this as phishing.
2 of 13 categories showed signals
We check every URL against 13 distinct scam categories so the verdict tells you not just how risky the page is, but what kind of risk it carries. Each meter pulls from page signals, web reports, our AI analyst, vision, and the scam-network cluster — not from raw AV labels.
- AI analyst tagged this as malware / drive-by / cracked app.
- AI analyst tagged this as phishing.
Malware distribution detected
Signals suggest this page may deliver malicious files or exploit the browser.
- Do not interact with kelvora.cfd
Do not enter credentials, deposit money, download files, or install browser extensions from this site.
- If you downloaded or ran a file from here
Disconnect the device from the internet, run a full scan with a reputable antivirus (Malwarebytes, ESET, Bitdefender), and consider a second-opinion scanner. Change passwords on any account you used from the device afterwards — ideally from a different device.
- OpenGet free cleanup help
MalwareTips has a dedicated malware-removal team who walk you through cleanup one-on-one.
Reputation Sources
How this domain rates across independent threat-intelligence and blocklist providers.
Referenced Domains
Outbound domains this page links to or loads resources from. Each links to its own security scan.
Safety FAQ
Common questions about this site, answered directly from the scan data above — so the answers always reflect the latest verdict on this page.
- Our automated security review flags kelvora.cfd as dangerous. Multiple threat indicators were detected — treat the site as a scam until proven otherwise.
- No — kelvora.cfd scored 25/100 on our trust scale. We detected active threat indicators, so we recommend avoiding the site entirely.
- Yes. kelvora.cfd presents a valid TLSv1.3 certificate issued by Let's Encrypt · E7, expiring in 39 days. Note that SSL only encrypts the connection — it does not guarantee that the site itself is trustworthy.
- kelvora.cfd is 3 months old, registered on 2/18/2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED. Scam domains are often freshly registered — a site under 6 months old warrants extra caution.
- 2 out of 91 antivirus engines in our malware network flagged kelvora.cfd as malicious or suspicious. Even one detection is a meaningful signal.
- No. kelvora.cfd is not currently listed on the major browser blocklist feeds that modern browsers use.
- kelvora.cfd resolves to an IP operated by Cloudflare, Inc. in US (usage type: Content Delivery Network). Hosting location alone doesn't make a site good or bad, but unusual geography for a brand's claimed country is one of many signals we weigh.
- Independent trust-rating sites currently show the following for kelvora.cfd: ScamAdviser: 40/100. Those scores come from user reviews and their own heuristics, so they are worth comparing against our verdict.
User reviews & comments(0)
Share your experience — "Lost $200 on a fake checkout" is more useful than "Scam". Your review helps others avoid traps.