krab1[.]id
Phishing- und Sicherheitsprüfung für krab1.id
“Kraken — официальный даркнет-маркетплейс, закрытая площадка”
krab1.id — Inhalt nicht verfügbar (HTTP 502). Markenidentität: Kraken; Betrugstyp: Crypto Scam. Zusammenfassung der Beweislage: VirusTotal 3/95 (Fortinet, Gridinsoft, SOCRadar); PhishDestroy score 65/100. Registrar: PT Beon Intermedia.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
The domain krab1.id was registered on 2025-12-09 through PT Beon Intermedia and is configured to use the Cloudflare nameservers dell.ns.cloudflare.com and newt.ns.cloudflare.com. DNS resolution points to the IPv6 address 2606:4700:3031::ac43:db78, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The site’s HTML title reads "Kraken — официальный даркнет‑маркетплейс, закрытая площадка", explicitly referencing the Kraken brand and suggesting a dark‑net marketplace. According to the provided intelligence, the page is classified as a crypto‑scam and employs brand impersonation of Kraken.
The infrastructure appears on a single security blocklist and is currently listed as blocked by PhishDestroy. VirusTotal analysis shows that three out of ninety‑five security vendors have flagged the domain, indicating partial detection. No SSL certificate is presented, and the HTTPS handshake fails, which is consistent with the reported offline status. The risk level is elevated, and the domain is marked as offline at the time of this report (2026-07-24).
Defenders should add krab1.id to network‑level deny lists, monitor the associated Cloudflare IP for any new activity, and consider the registrar PT Beon Intermedia as a potential source of additional malicious domains. Continuous observation of the Cloudflare ASN for similar impersonation campaigns is recommended, as is reviewing any future DNS changes that could reactivate the domain. The lack of a valid TLS certificate and the limited detection footprint suggest a low‑maturity operation, but the explicit brand targeting and cryptocurrency focus warrant heightened vigilance.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Archivierte Beweise
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt