kra--51[.]cc
“KRAKEN”
Gespeicherte Beobachtung
Beobachteter Titelkontrast
Zusammenfassung der Beweislage
The domain kra--51.cc was observed on July 12, 2026 and is classified as a high‑risk brand‑impersonation campaign targeting the cryptocurrency exchange Kraken. The site returns an HTTP 301 redirect and presents the page title “KRAKEN”, indicating a deliberate attempt to lure users familiar with the legitimate brand. The domain was created on February 21, 2026 and remains active at the time of reporting. Infrastructure analysis shows the domain is registered through NiceNIC International Group Co., Limited. Authoritative name servers are miguel.ns.cloudflare.com and raquel.ns.cloudflare.com, both operated by Cloudflare. DNS resolution points to IP address 172.67.187.16, which belongs to AS13335 Cloudflare, Inc., located in the United States. The site is protected by a Let’s Encrypt certificate (CN E8) and leverages Cloudflare Browser Insights and HTTP/3, confirming the use of Cloudflare’s edge services. Threat intelligence indicates the domain appears on three independent blocklists, including PhishDestroy, MetaMask, and SEAL. AlienVault OTX has catalogued the domain in one pulse, and VirusTotal reports that 11 out of 95 scanned security vendors flag the domain as malicious. Gridinsoft assigns a trust score of 0 out of 100. No additional content analysis beyond the page title is available, leaving the exact phishing payload and credential‑capture mechanisms unverified. Defenders should proactively block all traffic to kra--51.cc at the DNS and proxy layers, and monitor for any outbound connections to the underlying Cloudflare IP address. Given the brand‑impersonation aspect, security teams should update user‑awareness material to reference this specific campaign and enforce multi‑factor authentication for Kraken accounts. Continuous re‑evaluation is advised, as the threat actor may modify the payload or host new pages under the same infrastructure.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
Domainstatus
Erreichbar → Nicht erreichbar
-
Domainstatus
Nicht erreichbar → Erreichbar
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of kra--51.cc · checked Mar 2, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt