krk44[.]at
“Krа47.at | Krа47.cc - Проверка браузера - krab1.cc | krab1.at”
ملخص الأدلة
Analysis of krk44.at indicates a high‑confidence malicious profile despite the domain being taken offline at the time of review. The site previously responded with HTTP 200, and its SSL certificate was issued to PhishDestroy / botadmin.destroy.tools, a known indicator of phishing infrastructure. The certificate and the fact that the domain resolves to 172.67.222.128, an address owned by AS13335 Cloudflare, Inc., suggest the operators leveraged Cloudflare’s CDN and DNS services (luke.ns.cloudflare.com and rosalie.ns.cloudflare.com) to obscure the true hosting location. The registrar listed is Hosting Concepts B.V. d/b/a Registrar.eu, which is a legitimate registrar but does not mitigate the malicious intent observed.
Gridinsoft assigned a trust score of 0 / 100, effectively flagging the domain as completely untrusted. The page title captured during the brief availability – “Krа47.at | Krа47.cc - Проверка браузера - krab1.cc | krab1.at” – contains Russian text referring to a “browser check” and references to krab1, a pattern seen in other crypto‑drainer campaigns that use language obfuscation to evade detection. The domain appears on one security blocklist and was flagged by four of ninety‑three VirusTotal scanners, reinforcing the suspicion of abuse. The identified scam type is a Crypto Scam, consistent with the observed indicators.
Defenders should immediately block krk44.at at perimeter firewalls and DNS resolvers, monitor for any re‑registration of the same name or related subdomains, and consider adding the associated IP range (172.67.222.128) to threat‑intel feeds. Continuous observation of Cloudflare‑associated IPs used by the domain is advised, as the actors may shift infrastructure while retaining the same CDN front‑end.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
-
VirusTotal
4 ← 7
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب