The domain dogecoin-crypto.ru was registered on May 18, 2021 through the BEGET-RU registrar and continues to resolve to the IPv4 address 87.236.16.13. Current DNS records list six nameservers: ns1.beget.com, ns1.beget.pro, ns1.beget.ru, ns2.beget.com, ns2.beget.pro, and ns2.beget.r. The domain is presently active and has been flagged by multiple defensive services.
VirusTotal reports that 2 of 91 security vendors have identified the domain as malicious, indicating a modest but non‑trivial level of detection across the scanning ecosystem. PhishDestroy has already blocked the domain, and it appears on one external security blocklist, reinforcing the view that the infrastructure is being actively monitored by threat‑mitigation platforms. The limited detection count suggests that the site may be employing evasion techniques or that it has only recently entered a broader campaign.
No additional public data such as SSL certificates, HTTP response codes, or page titles have been published, leaving the exact content and lure mechanisms unverified. Defenders should continue to block the domain at network borders, update endpoint and DNS filtering policies to include the observed IP address and associated nameservers, and monitor for any new indicators that may emerge from additional scans. Ongoing observation of the domain’s activity, especially any changes to its hosting or registration details, is recommended to assess whether the threat actor expands the campaign or modifies its infrastructure.