kra46-at[.]banketivanovo[.]ru
“kra46-at.banketivanovo.ru”
kra46-at.banketivanovo.ru — Inhalt nicht verfügbar. Betrugstyp: Banking Phishing. Zusammenfassung der Beweislage: VirusTotal 12/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Fortinet); Google Safe Browsing flagged; PhishDestroy score 86/100. Registrar: REGRU-RU.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Analysis of kra46-at.banketivanovo.ru confirms its classification as a high-risk banking phishing domain, currently offline but previously active. The domain was registered on January 7, 2025, through REGRU-RU, a registrar frequently associated with malicious infrastructure. It resolved to 193.105.134.30, an IP address geolocated in Sweden and assigned to AS42237 (w1n ltd), a hosting provider commonly linked to phishing and fraudulent activities. No SSL certificate was detected, increasing the likelihood of interception or tampering during data transmission.
The domain was flagged by 12 of 95 security vendors on VirusTotal, indicating moderate but not universal detection. It appears on at least one security blocklist, specifically PhishDestroy, and is classified under Google Safe Browsing as a social engineering threat. The page title, matching the domain name (kra46-at.banketivanovo.ru), provides no additional brand-specific context, though the scam type is explicitly identified as banking phishing in available intelligence. Nameservers ns1.regerey.com and ns2.regerey.com further suggest ties to infrastructure previously observed in phishing campaigns.
Gridinsoft assigns the domain a trust score of 0/100, reinforcing its malicious classification. While the exact content of the phishing page remains unanalyzed, the combination of registrar, hosting provider, detection rates, and blocklist inclusion strongly supports its use in credential harvesting or financial fraud targeting Russian-speaking users. Defenders should treat this domain as compromised and prioritize blocking both the domain and its resolving IP (193.105.134.30) at the network level. Monitoring for re-registration or re-emergence under similar naming conventions (e.g., banketivanovo.ru variants) is recommended, as threat actors often reuse infrastructure patterns.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt