kra46-at[.]majestic-mta[.]ru
“kra46 - AT автоматизация бизнес-процессов”
kra46-at.majestic-mta.ru — Inhalt nicht verfügbar. Zusammenfassung der Beweislage: VirusTotal 7/95 (alphaMountain.ai, CyRadar, Fortinet, Kaspersky, Lionic); PhishDestroy score 71/100. Registrar: REGRU-RU.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Analysis of kra46-at.majestic-mta.ru shows a domain registered through REGRU-RU on December 11, 2024. The authoritative name servers are ns1.armadns.icu and ns2.armadns.icu, both hosted on the armadns.icu infrastructure. DNS resolution points to IP address 193.105.134.30, which is allocated to AS42237 (w1n ltd) and geolocated to Sweden. No SSL certificate is presented for the host, indicating that any web service would be delivered over plaintext HTTP.
The site’s page title, "kra46 - AT автоматизация бизнес-процессов," translates to a business‑process automation reference, but no specific brand or legitimate service is identified in the title. The domain is currently taken offline, yet it remains listed on at least one security blocklist, with PhishDestroy explicitly blocking it. VirusTotal scans have flagged the domain by seven of ninety‑five security vendors, reinforcing the suspicion of malicious intent. Gridinsoft assigns a trust score of 0 out of 100, the lowest possible rating, suggesting a high likelihood of abuse.
The combination of a recent registration date, lack of TLS, low trust score, blocklist presence, and multiple vendor detections aligns with the generic phishing classification. Uncertainty remains regarding the exact content that was served before the takedown, as no live HTTP response or content snapshot is available. Defenders should continue to block the domain and its associated IP at network perimeters, add the IP to reputation feeds, monitor for any re‑hosting attempts, and ensure that any inbound traffic to the host is denied. Ongoing surveillance of the AS42237 range is advised, as the infrastructure may be reused for related campaigns.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt