kra48att[.]cc
“kra48att.cc”
اكتشاف محفوظ
تنبيه إخفاء المحتوى
- نوع الإخفاء
status_split- درجة الإخفاء
- 4/6
ملخص الأدلة
PhishDestroy identifies kra48att.cc as an active credential theft domain operating under a generic phishing campaign. The domain was registered on November 19, 2025, and remains unblocked by most defenses despite clear malicious indicators. Current status is classified as elevated risk, with threat actors leveraging the domain to harvest login credentials under false pretenses. The domain resolves to IP address 185.226.92.168 and was created on November 19, 2025. Security telemetry confirms kra48att.cc has been flagged by 10 of 95 VirusTotal vendors, with additional risk factors including a Let's Encrypt SSL certificate issued for increased deception. The domain is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently observed in phishing infrastructure due to lax oversight. While specific blocklist counts are not publicly disclosed, the combination of low trust scores and high VT detection rate underscores the domain’s hostile nature. Users and organizations are strongly advised to block kra48att.cc at the DNS and firewall levels. Network defenders should inspect outbound traffic for connections to 185.226.92.168 and audit logs for any interactions with the domain. End users must be warned against entering credentials or sensitive information into any page hosted on kra48att.cc. Immediate remediation includes updating blocklists, reviewing SIEM alerts for related hashes or IPs, and conducting phishing awareness training to prevent account compromise.
لقطة الأدلة المرسلة
- أُرسل
- سجلات الدفتر
- 1
- معرّف القضية
PD-20260326-20D01F- عنوان الصفحة الملتقطة
- kra48att.cc/
- ملف PDF
- دليل PDF
النص الكامل للدليل
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | kra48att.cc |
malicious | Sinkholed |
| DNS4EU | kra48att.cc |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
حالة النطاق
يتعذر الوصول إليه ← يمكن الوصول إليه
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب