# kra-32cc.com — MALICIOUS > kra-32cc.com is flagged for credential theft with 10 out of 95 VirusTotal detections. Users should avoid interaction and enhance security measures. ## Summary PhishDestroy identifies kra-32cc.com as an active credential theft threat. This domain does not appear linked to a specific brand but is associated with generic credential harvesting activities often used to steal login information from unsuspecting victims. Technical indicators reveal kra-32cc.com has a VirusTotal detection rate of 10 out of 95 security vendors flagging the domain. It was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on February 8, 2025. The domain resolves to IP address 188.114.96.3 and uses a Let's Encrypt SSL certificate. Google Safe Browsing does not currently flag it, but it appears on one additional security blocklist and is blocked by MetaMask, indicating risks related to cryptocurrency environments. Currently, kra-32cc.com remains active and poses an elevated risk primarily through credential theft schemes. Users are advised not to engage with this domain or provide any personal information. Network defenders should consider blocking this domain and monitoring for any related suspicious activity. Continuous vigilance is necessary as the domain may evolve or expand its threat capabilities. ## Threat Details - Verdict: MALICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2025-02-08 00:28:46 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 188.114.96.3 ## Detection Status - VirusTotal: 10 vendors flagged - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["MetaMask"] ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/9abda0a3-110d-453a-9b46-e105afe03500 - PhishDestroy: https://phishdestroy.io/domain/kra-32cc.com/ - LLM endpoint: https://phishdestroy.io/domain/kra-32cc.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/kra-32cc.com/ Last updated: 2026-03-27