الانتقال إلى تقرير الأمان
⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 17. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
أمن المجال وذكاء التهديدات

kra30c[.]cc

“kra30c.cc”

حكم التهديد حرجة 100/100 درجة الأدلة
التوفر آخر نشاط معروف أحدث مراقبة إمكانية الوصول المخزنة
اكتشافات VirusTotal: 17/91 نوع الاحتيال: Credential Phishing آخر نشاط معروف
OTX: 1 ref 15/06/2026

ملخص الأدلة

حرج
Evidence score
100/100

This domain, kra30c.cc, is identified as a fake login portal designed to harvest user credentials through deceptive authentication interfaces. Analysis indicates the infrastructure mimics legitimate login pages, likely targeting users of cryptocurrency platforms, financial services, or other high-value accounts. The domain employs social engineering tactics, such as urgent prompts or fake security alerts, to trick visitors into entering sensitive information, which is then exfiltrated to attacker-controlled servers. Infrastructure analysis reveals multiple technical indicators supporting this assessment. The domain is flagged by 14 out of 95 security vendors on VirusTotal, indicating widespread detection as malicious. It was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on March 29, 2026, a date inconsistent with typical domain lifecycle patterns, suggesting potential abuse. The domain appears on one security blocklist and resolves to the IP address 103.224.212.210, hosted by Trellian Pty. Limited in Australia. The SSL certificate, issued by Let's Encrypt (R13), is commonly used in both legitimate and malicious infrastructure, providing minimal assurance of safety. Users who visited kra30c.cc should take immediate action to mitigate potential compromise. If credentials were entered, affected accounts must be secured by changing passwords and enabling multi-factor authentication where available. Review connected devices and sessions for unauthorized access, particularly for financial or cryptocurrency accounts. Monitor for unusual activity, such as unauthorized transactions or login attempts, and report any suspicious behavior to the relevant platform. Consider scanning the device used to access the domain for malware, as fake login portals may deploy additional payloads to maintain persistence or exfiltrate further data.

VirusTotal
VirusTotal
17 det.
OTX references
شهادة TLS
منتهية الصلاحية أو غير متحقق منها -7d
العمر
4 mo
الحالة المرصودة
آخر نشاط معروف HTTP 200
PhishDestroy
قائمة الإتلاف
مدرج

Data Coverage

VirusTotal 17 / 91 URLQuery لم يتم التحقق منها PhishStats لم يتم التحقق منها OTX 1 community reference رادار CF no data URLScan capture not submitted URLScan verdict التقييم غير متاح حجب عناوين DNS لم يتم التحقق منها TLS منتهية الصلاحية أو غير متحقق منها WHOIS 4 mo old لقطة شاشة لم يتم تسجيله سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكاتRegistrar context
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
8/10

تغطية قوائم الحظر

١٠ مصادر خارجية مراقبة · لقطة محفوظة 10/08/2026

١٠ مصادر خارجية مراقبة لا تطابق

معلومات النطاق

النطاق
الخادم / ASN Apache · AS133618 Trellian Pty. Limited
سمعة عنوان IP IP abuse confidence 0/100 0 reports checked 14/07/2026
مسجّل النطاق NiceNIC RU(RU) PhishDestroy Investigation
عنوان IP 103.224.212.210 AU
الموقع الجغرافيAU Beaumaris, AU
الشبكةAS133618 · Trellian Pty. Limited
التسجيلتم إنشاؤه 29/03/2026 (134d)
حالة HTTP200
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
تاريخ أول اكتشاف15/06/2026
خوادم الأسماءexpired-ns2.niceisp.com
بصمة TLS
رصد TLSصالح منذ 06/05/2026فُحص في 07/05/2026
الأسماء البديلة لموضوع TLS111-90-145-179.xyz123moviesnew.xyz18fuliwang.xyz1wxvup.xyz1xveg.xyz1xwiv.xyz432c51d93777.xyz4lordfilm-0.xyz7fdah3n.xyza3t7h348zy3bn6tj6vwg.xyzaboutprize.xyzalex-s1.xyzaltyrceq.xyzamericanhomesteaders.xyzammser.xyz+29
عنوان الصفحة
kra30c.cc
شهادة TLS
منتهية الصلاحية أو غير متحقق منها · صادرة عن Let's Encrypt / R13
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

17 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed Previous stored snapshot: 15 detections
ADMINUSLabs
alphaMountain.ai
Bfore.Ai PreCrime
BitDefender
Chong Lua Dao
CyRadar
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
كاسبرسكي
LevelBlue
Lionic
سوفوس
VIPRE
Webroot
تحليل إعدادات الموقع
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
/cpx.php /medios1.php /toolbar.php /check_image.php /check_popunder.php

هل تأثرت بهذا الموقع؟

If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك

تحقق من أي نطاق

تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة

امسح الآن

الإبلاغ عن محاولة تصيد احتيالي

أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع

إبلاغ

تحديثات فورية حول التهديدات

تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة

مراقبة

ابقَ على اطلاع، وابقَ آمنًا

راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب

تحديثات فورية حول التهديدات الاعتراض على هذا الإعلان

أدوات خارجية

HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/kra30c.cc"
  title="PhishDestroy threat report for kra30c.cc"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>