kr3.cc
Evidence Summary
PhishDestroy first observed kr3.cc on Aug 17, 2026. Current evidence score: 88/100 (critical).
One source contains a positive finding: VirusTotal. VirusTotal recorded 8 detections among 91 engines: alphaMountain.ai, BitDefender, ESET, Forcepoint ThreatSeeker, G-Data, Gridinsoft, SOCRadar, VIPRE on Aug 27, 2026 at 03:16 UTC. Non-positive and contextual checks: AlienVault OTX listed 3 community pulse references (not vendor detections) on Aug 19, 2026 at 05:26 UTC. The separate external-blocklist snapshot contained no matches on Sep 15, 2026 at 18:20 UTC. Google Safe Browsing returned no flag on Aug 19, 2026 at 05:25 UTC.
HTTP 301 was recorded on Sep 15, 2026 at 11:00 UTC. Latest classified outcome: redirect observed; cause http redirect on Sep 15, 2026 at 00:25 UTC. Registration records for the domain list NICENIC INTERNATIONAL GROUP CO., LIMITED as the registrar. At collection time, the hostname resolved to 188.114.96.3 on AS13335 (Cloudflare, Inc.). The IP and ASN identify shared Cloudflare edge infrastructure; the origin server is not established by this address. TLS metadata lists Google Trust Services as the certificate issuer with validity through Nov 5, 2026; checked Aug 17, 2026 at 13:02 UTC.
Neither a page title nor a landing-page capture is stored. Only one source contains a positive finding; no second positive source is stored. The stored fields do not identify an impersonated brand or victim interaction.
Network Security Intelligence Registrar context
Forensic History & Detection Timeline
-
Domain Status Transition Sep 14, 2026 · 00:18 UTCDomain state transitioned from dead to alive.
-
Domain Status Transition Sep 13, 2026 · 00:56 UTCDomain state transitioned from alive to dead.
-
Domain Status Transition Aug 20, 2026 · 00:15 UTCDomain state transitioned from dead to alive.
-
Domain Status Transition Aug 19, 2026 · 04:43 UTCDomain state transitioned from alive to dead.
-
VirusTotal Detections Update Aug 18, 2026 · 00:57 UTCVirusTotal scanner detections updated from 6 to 7. Added scanner alerts: SOCRadar.
-
Threat First Observed Aug 17, 2026 · 12:33 UTCDomain ingestion complete. Initial state is marked as alive.
Threat Response Pipeline
Public Blocklist Status
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
Latest Classified Outcome 2026-09-15 02:25:57 UTC
Technologies · 2 identified
VirusTotal Analysis
Stored outcome evidence
Outcome & takedown attribution
- Outcome
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive