kra28c[.]cc
ملخص الأدلة
The domain kra28c.cc is currently identified as a credential harvesting phishing site, targeting users through deceptive login portals designed to capture authentication credentials. Analysis confirms the domain is presently offline, though prior activity indicates it was actively serving malicious content. No specific brand impersonation has been conclusively linked to this domain, though the credential harvesting methodology suggests potential targeting of financial or corporate login systems. Infrastructure analysis reveals kra28c.cc was flagged by 13 of 95 security vendors on VirusTotal, indicating a moderate consensus on its malicious nature. The domain was registered through Gname 200 Inc on March 29, 2026, an unusually future-dated registration that may suggest domain generation algorithm usage or administrative error. It resolved to the IP address 188.114.97.3, hosted by a content delivery network provider in Canada, which is a common tactic to obscure origin infrastructure. The domain appears on one security blocklist and utilized a Let's Encrypt SSL certificate (serial number E7), providing a false sense of legitimacy to end users. The combination of these indicators—particularly the future creation date and low blocklist prevalence—suggests either a newly deployed campaign or an attempt to evade detection through unconventional registration practices. Current status indicates kra28c.cc has been taken offline, likely in response to detection and mitigation efforts. However, the domain's infrastructure and registration details remain a concern, as threat actors may reactivate or repurpose it for future campaigns. Organizations and users are advised to implement proactive measures, including blocking the domain and its associated IP address at the network perimeter. Security teams should monitor for related domains with similar naming patterns or registration characteristics, particularly those using the same registrar or resolving to adjacent IP ranges. Endpoint protection systems should be updated to include this domain in phishing detection rules, and users should be educated on recognizing credential harvesting attempts, especially those leveraging SSL certificates to appear legitimate. Given the elevated risk level, continuous monitoring of this domain and its infrastructure is recommended to prevent potential resurgence.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 10/08/2026
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب