rich-brain[.]ru
“krab1 - образовательная AT платформа финансового мышления”
Zusammenfassung der Beweislage
Analysis of the domain rich-brain.ru indicates it was operating as a financial-themed phishing platform targeting Russian-speaking users. The page title, 'krab1 - образовательная AT платформа финансового мышления,' suggests the site posed as an educational or investment training service, though the exact content and functionality remain unverified. The domain was registered on October 1, 2025, through REGRU-RU and resolved to the IP address 193.105.134.30, hosted on AS42237 (w1n ltd) in Sweden. No SSL certificate was detected, increasing the risk of unencrypted data transmission. The domain appears on one security blocklist and was flagged by PhishDestroy.
Two of 95 security vendors on VirusTotal identified the domain as malicious, though this does not confirm widespread detection. Nameservers (ns1.regerey.com, ns2.regerey.com) and the registrar (REGRU-RU) are consistent with infrastructure used in other phishing campaigns, though no direct links to known threat actor groups or phishing kits have been established. The Gridinsoft trust score of 0/100 further supports the assessment of elevated risk. As of the report date, the domain is offline, though defenders should monitor for reactivation or migration to new infrastructure.
Network defenders are advised to block the domain and its resolving IP (193.105.134.30) at the perimeter. Security teams should review logs for connections to this IP or domain, particularly from users who may have interacted with financial or educational-themed phishing lures. Additional investigation into the hosting provider (AS42237) and nameserver operator (regerey.com) may reveal related malicious domains. No brand impersonation was confirmed from the available data, but the financial focus aligns with common phishing objectives.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 12.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt