krab1-cc[.]kartina-m[.]ru
“krab1-cc.kartina-m.ru”
krab1-cc.kartina-m.ru — المحتوى غير متوفر. ملخص الأدلة: VirusTotal 10/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Fortinet); Google Safe Browsing flagged; PhishDestroy score 80/100. مسجّل النطاق: REGRU-RU.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of krab1-cc.kartina-m.ru indicates that the domain was registered on March 06, 2025 through the REGRU‑RU registrar and is hosted on a server located in Sweden, ASN AS42237 operated by w1n ltd, reachable at 193.105.134.30. The authoritative name servers are ns1.regerey.com and ns2.regerey.com. No TLS certificate is presented, meaning the site is served only over HTTP. The page title returned by the server is identical to the domain name, providing no additional context.
Reputation services have flagged the domain: ten of ninety‑five VirusTotal scanners reported it as malicious, Google Safe Browsing classifies it as a social‑engineering threat, and it appears on a single security blocklist. PhishDestroy has taken the domain offline, and the current status is reported as offline. Gridinsoft assigns a trust score of zero out of one hundred, reinforcing the malicious assessment. The domain is listed as a generic phishing campaign, but the specific target brand or credential‑stealing page has not been disclosed in the available intelligence.
Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any residual traffic to 193.105.134.30, and consider adding the IP address to host‑based deny lists. Because the site lacks SSL, any attempted connections would be unencrypted, allowing potential interception, but the primary risk remains credential harvesting. Continuous observation of the registrar REGRU‑RU and the hosting ASN is advised to detect possible re‑use of the infrastructure for future campaigns.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب