Analysis indicates that the domain krak72.cc was registered through Dynadot Inc on 28 September 2025 and is currently active. The authoritative name servers are a.dnspod.com, b.dnspod.com and c.dnspod.com, which are typical of domains managed via DNSPod. DNS resolution points to the IPv4 address 193.187.110.3. This IP address is associated with a hosting provider that has previously been observed serving malicious web content, although no specific attribution is available in the current dataset. Threat intelligence sources have marked krak72.cc as malicious.
The anti‑phishing service PhishDestroy has actively blocked the domain, and it appears on at least one public security blocklist. On VirusTotal, eight of ninety‑one scanning engines returned a positive detection, confirming that multiple independent scanners recognize the domain as harmful. The detections are consistent with a generic phishing classification, but no further detail such as targeted brand or specific phishing kit has been disclosed. The available evidence does not include a TLS certificate fingerprint, HTTP response codes, page title, or any Safe Browsing verdict beyond the blocklist entries. Consequently, the presence of HTTPS, the content served, and the exact phishing lure remain uncertain.
Likewise, open‑source threat feeds such as OTX have not published additional indicators linked to this domain at the time of analysis. Given the confirmed blocklist entries, the active block by PhishDestroy, and the multi‑engine VirusTotal detections, defensive operators should treat krak72.cc as a high‑risk indicator. Recommendations include adding the domain to corporate deny lists, configuring web proxies to block outbound connections to the resolved IP 193.187.110.3, and monitoring DNS queries for the associated nameservers. Continuous re‑evaluation is advised, as further analysis may reveal additional payload characteristics or victim targeting.