ww16[.]kraken10[.]co
“kraken10.co”
ww16.kraken10.co — مغطى بعباءة · يمكن الوصول إليه (HTTP 502). انتحال العلامة التجارية: Kraken; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 0/94; cloaking observed; PhishDestroy score 80/100. مسجّل النطاق: Above.com Pty.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy identifies ww16.kraken10.co as an active brand impersonation threat under investigation. This domain mimics Kraken, a prominent cryptocurrency exchange, with the intent to deceive users into surrendering sensitive credentials or digital assets. While no drainer kit has been directly observed at this stage, the domain’s structure and naming convention strongly suggest a phishing operation targeting Kraken’s user base. The threat actor likely leverages social engineering tactics, such as spoofed emails or fake support links, to lure victims to the fraudulent site.
This domain was flagged with the following technical indicators: it currently shows 0 out of 95 detections on VirusTotal, indicating a low immediate detection rate. Registered through Above.com Pty Ltd., the domain resolves to IP address 64.190.63.136. The SSL certificate was issued by DigiCert Inc, and the domain was created on May 24, 2025. As of the latest assessment, Google Safe Browsing (GSB) has not flagged the domain, and no blocklist entries have been recorded. These attributes suggest a recently deployed and potentially low-profile threat.
The domain remains active and is considered a high-priority investigative target due to its clear intent to impersonate a well-known brand. No active takedown efforts have been confirmed, leaving the risk of continued user exposure elevated. Users are strongly advised to avoid accessing ww16.kraken10.co or any subpages under kraken10.co. Organizations should add the domain and its associated IP to network blocklists and monitor for inbound or outbound connections. Additionally, users of Kraken or similar services should verify URLs carefully, enable multi-factor authentication, and report suspicious communications. The remaining risk is assessed as moderate-to-high pending further forensic analysis and potential takedown actions.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
PD-20260328-6098D9 Recipient: abuse@above.com هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب