kra46at[.]ideltower[.]ru
“kra46 - AT архитектурный концепт высотных зданий”
kra46at.ideltower.ru — Inhalt nicht verfügbar. Zusammenfassung der Beweislage: VirusTotal 10/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Fortinet); PhishDestroy score 80/100. Registrar: REGRU-RU.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Analysis of the domain kra46at.ideltower.ru shows that it was registered on December 11, 2024 and subsequently resolved to the IPv4 address 193.105.134.30, which is hosted within Autonomous System AS42237 operated by w1n ltd in the Southeast region. The domain is delegated to the name servers ns1.armadns.icu and ns2.armadns.icu, and no TLS certificate was observed during the scan, indicating that the site was served over plain HTTP only. The page title returned by the server was "kra46 - AT архитектурный концепт высотных зданий," suggesting the site attempts to present itself as an architectural concept service for high‑rise buildings, possibly targeting Russian‑speaking users.
The domain is currently taken offline, but historical data indicates that it was flagged by multiple security controls: PhishDestroy listed the domain as blocked, VirusTotal recorded detections by 10 of 95 AV engines, and at least one public blocklist contained the address. The Gridinsoft trust score of 0/100 further reinforces its malicious classification. Registrar information points to REGRU‑RU, a Russian registrar, which aligns with the Cyrillic page title.
While the exact phishing kit or credential‑harvesting page has not been captured, the combination of a newly created domain, lack of SSL, low trust metrics, and multiple vendor detections supports an elevated risk rating. Defenders should add the IP 193.105.134.30 and the domain to network‑level blocklists, monitor DNS queries for this host, and ensure that any inbound traffic to the associated name servers is dropped. Continuous re‑evaluation is advised in case the actor re‑hosts the payload on a different address, as the infrastructure components (registrar and hosting ASN) remain active.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt