Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@netcup.de.
The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
kanzlei-krimhand[.]de
“Русскоязычные адвокаты в Германии | Krimhand Rechtsanwaltkanzlei”
kanzlei-krimhand.de — Nicht bestätigt. Betrugstyp: Credential Phishing. Zusammenfassung der Beweislage: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); URLQuery 1 alert; PhishDestroy score 76/100.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain, kanzlei-krimhand.de, is identified as a potential credential theft threat. It is actively being used to impersonate a legal service by targeting Russian-speaking individuals in Germany. This type of attack aims to collect sensitive personal information from unsuspecting users, which can lead to identity theft and financial loss.
Current analysis shows that the domain is listed on one security blocklist, specifically PhishDestroy, indicating a recognized risk. VirusTotal reports that 1 out of 95 security vendors have flagged this domain as malicious. The domain is registered under a reputable registrar, with an active SSL certificate issued by Let's Encrypt, suggesting that it may employ encryption to give a false sense of security. The domain resolves to an IPv6 address (2a03:4000:30:746c::12:9982) located in Germany, managed by netcup GmbH, which is notable as it can contribute to the trustworthiness perception among users.
Users who have visited kanzlei-krimhand.de should take immediate precautions. It is recommended to change passwords for sensitive accounts and monitor financial statements for any unauthorized transactions. Additionally, users should perform a thorough security scan of their devices to detect potential malware or spyware. Awareness of phishing schemes, especially those targeting specific demographics, is crucial in preventing credential theft and safeguarding personal information.
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | kanzlei-krimhand.de |
malicious | Sinkholed |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Analyse der Website-Konfiguration
Nachweise und externe Berichte
PD-20260617-5BAF4E Recipient: abuse@netcup.de Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt