kra35at[.]cc
“KRAKEN”
Zusammenfassung der Beweislage
The domain kra35at.cc was registered on 2025-01-02 through NiceNIC International Group Co., Limited and resolves to the Cloudflare‑owned address 172.67.144.56 (ASN 13335, United States). Its authoritative nameservers are amalia.ns.cloudflare.com and moura.ns.cloudflare.com, indicating the infrastructure is fully proxied by Cloudflare. The site presents the page title “KRAKEN”, matching the declared brand target Kraken.
TLS termination is provided by a Google Trust Services certificate issued to the WE1 organization, confirming the use of a legitimate public‑key infrastructure. HTTP responses return a 301 redirect, and traffic is served over HTTP/3 with Cloudflare Browser Insights enabled. The domain appears on a single security blocklist and is currently blocked by PhishDestroy. Reputation scoring from Gridinsoft is 0 out of 100, and VirusTotal analysis shows nine out of ninety‑five scanners flagging the host as malicious.
Analysis of the available intelligence classifies kra35at.cc as a high‑risk brand‑impersonation campaign targeting users of the Kraken cryptocurrency exchange. The scam type is identified as cryptocurrency, and the page title “KRAKEN” is used to lure victims. Combined indicators—low trust score, multiple vendor detections, and active status—support a conclusion that the domain is being used to deceive users for financial gain.
Defenders should add kra35at.cc to outbound and inbound filtering rules and ensure it is blocked at DNS resolvers and proxy layers. Continuous monitoring of Cloudflare‑associated IP ranges for new domains with similar naming patterns is advised. Security teams should also update detection signatures to flag HTTP 301 responses that present the “KRAKEN” title when served from Cloudflare infrastructure. Incident response playbooks should treat any traffic to this domain as malicious and alert SOC analysts for immediate investigation.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
Erkennungszeitleiste
-
VirusTotal
9 → 7
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of kra35at.cc · checked Mar 2, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt