kra46-cc[.]farmaciaitali24[.]ru
“kra46 - круглосуточный CC-помощник в мире итальянской медицины”
kra46-cc.farmaciaitali24.ru — المحتوى غير متوفر. نوع الاحتيال: Investment Scam. ملخص الأدلة: VirusTotal 13/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; PhishDestroy score 89/100. مسجّل النطاق: REGRU-RU.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of kra46-cc.farmaciaitali24.ru shows a high‑risk investment phishing operation that has been taken offline as of the report date, July 23 2026. The domain was registered on December 11 2024 through the Russian registrar REGRU-RU and resolves to the IPv4 address 193.105.134.30, which is advertised as belonging to AS42237 w1n ltd in Sweden. No SSL certificate is present, indicating that the site served only HTTP content. The page title retrieved during earlier crawls reads "kra46 - круглосуточный CC‑помощник в мире итальянской медицины," suggesting a Russian‑language front that references the Italian medical sector, but the content has not been publicly released for further forensic review.
Reputation data shows the domain appears on a single security blocklist, PhishDestroy, and Google Safe Browsing flags it for social engineering. VirusTotal scans returned 13 detections out of 95 vendors, reinforcing the malicious classification. Gridinsoft assigned a trust score of zero out of one hundred, and the nameservers ns1.armadns.icu and ns2.armaddns.icu are associated with generic dynamic DNS services, a pattern often leveraged by threat actors to rapidly redeploy infrastructure. Given the offline status, immediate mitigation focuses on preventing re‑use of the hosting IP and the identified nameservers.
Defenders should add 193.105.134.30 to network blocklists, monitor for new domains registered with REGRU-RU that resolve to the same IP range, and enforce URL filtering for the domain and its parent zone. Continuous observation of PhishDestroy and Google Safe Browsing updates is advised to capture any re‑emergence of the site. The combination of multiple vendor detections, a zero trust score, and a targeted investment scam narrative warrants a high‑severity incident response and extended monitoring of related infrastructure.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب