krab2-cc[.]com
فحص التصيد والأمان للنطاق krab2-cc.com
“krab2.cc”
krab2-cc.com — آخر نشاط معروف (HTTP 200). ملخص الأدلة: VT 6/91 (alphaMountain.ai, Chong Lua Dao, CRDF, Fortinet, Gridinsoft); URLQuery 0; URLScan no malicious verdict; GSB no flag; Spamhaus DBL_PHISH; BL 0; PD 83/100. مسجّل النطاق: NiceNIC.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy first observed krab2-cc.com on Mar 27, 2026. Positive findings were recorded by VirusTotal and Spamhaus DBL. Evidence score: 83/100.
VirusTotal recorded 6 detections among 91 engines: alphaMountain.ai, Chong Lua Dao, CRDF, Fortinet, Gridinsoft, SOCRadar on Jul 27, 2026 at 03:23 UTC. Spamhaus DBL: DBL_PHISH on Jul 13, 2026 at 22:35 UTC. AlienVault OTX listed 1 community pulse reference (not vendor detections) on May 3, 2026 at 17:19 UTC. The external blocklist snapshot contained no matches on Aug 7, 2026 at 10:20 UTC. URLQuery recorded no positive detection. Google Safe Browsing returned no flag on Mar 28, 2026 at 07:00 UTC. URLScan completed without a malicious verdict (score 0).
HTTP 200 was recorded on Aug 7, 2026 at 10:38 UTC. Latest classified outcome: live content observed; cause content served on Aug 7, 2026 at 00:41 UTC. Registration records list NICENIC INTERNATIONAL GROUP CO., LIMITED as the registrar and Mar 27, 2026 as the registration date. At collection time, the domain resolved to 188.114.97.3. Captured page title: “krab2.cc”. IoC extraction completed on Jul 29, 2026 at 02:08 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysis13/07/2026
Analysis indicates that krab2-cc.com is an active credential-phishing domain targeting users of the legitimate service krab2.cc. The domain was registered on March 27, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, and currently resolves to the IP address 188.114.97.3, which is part of CloudFlare’s infrastructure in Canada. The use of CloudFlare nameservers (aleena.ns.cloudflare.com and jay.ns.cloudflare.com) and a 301 HTTP redirect suggests an attempt to mask the true origin of the phishing infrastructure while maintaining operational persistence. The domain is flagged by one threat intelligence pulse in AlienVault OTX and appears on a security blocklist, specifically PhishDestroy. Gridinsoft assigns it a trust score of 0/100, reinforcing its classification as high-risk. The SSL certificate, issued by Google Trust Services (WE1), is consistent with legitimate sites but does not mitigate the threat, as phishing domains frequently use valid certificates to appear credible. VirusTotal reports that 4 of 94 security vendors detect this domain as malicious, though the absence of additional context limits the granularity of this assessment. The page title, 'krab2.cc,' directly corresponds to the targeted service, indicating an intent to deceive users into believing they are interacting with the authentic platform. No specific phishing kit or brand impersonation details are available in the current intelligence, but the domain’s structure and behavior align with credential-harvesting campaigns. Defenders should treat this domain as actively malicious and implement blocking measures at the DNS or proxy level. Further investigation into the redirect chain and backend infrastructure may reveal additional indicators of compromise, such as associated IP ranges or connected domains.
استخبارات أمن الشبكات Registrar Integrity Alert
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
حصلت ICANN على أموالها. أما المساءلة فلم تصل.
بالنسبة إلى نطاق gTLD هذا، يعمل المسجّل المذكور أعلاه بموجب عقد مع ICANN. وتحصّل ICANN رسوماً سنوية ومتغيرة ورسومًا قائمة على المعاملات مرتبطة بعمليات التسجيل والتجديد والنقل.
الاعتماد: جرت الاستفادة منه مالياً. المساءلة: يُرجى التحقق مرة أخرى لاحقاً.
ثم يبدأ السحر: تكتب ICANN البند RAA §3.18، ويتولى المسجّل التحقيق في إساءة الاستخدام داخل قاعدة عملائه، ويقدّم الضحايا الأدلة مجاناً، بينما تنتظر كل طبقة أن يتحرك طرف آخر. إذا كان ذلك يجعل الضحايا يشعرون بمزيد من الأمان، فممتاز—لقد أدّت الفاتورة مهمتها.
Latest Classified Outcome 2026-08-07 02:41:42 UTC
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of krab2-cc.com · checked Mar 28, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
حول هذا التقرير: krab2-cc.com
يقدم هذا التقرير أحدث الأدلة المخزنة المتاحة لـ PhishDestroy. يتم عرض الطوابع الزمنية للمصدر حيثما كان ذلك متاحًا؛ يمكن أن تتغير أحكام التوفر والبائعين بعد التجميع.
عرض الموقع الذي تم التقاطه عنوان الصفحة “krab2.cc”.
اعتبارًا من 07/08/2026، كان لدى krab2-cc.com اكتشافات من محركات الأمان 6.
إذا كنت تعتقد أن هذه القائمة غير دقيقة، تقديم استئناف. للتعرف على منهجيتنا، قم بزيارة صفحة الأسئلة الشائعة.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب