# PhishDestroy threat dossier — kra38r.ru ================================================================ Fetched: 2026-04-25 12:37:55 UTC Canonical: https://phishdestroy.io/domain/kra38r.ru/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Generic Phishing Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: content_divergence) (score: 4/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/94 security vendors flagged this domain Flagging vendors: Seclookup, Webroot ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.96.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: RU-CENTER-RU Nameservers: aldo.ns.cloudflare.com, aldo.ns.cloudflare.com., alina.ns.cloudflare.com, alina.ns.cloudflare.com. Registered: 2026-03-28 Page title: 404 Not Found HTTP response: 404 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-03-28 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-03-29 01:20:59 UTC (by PhishDestroy tracker) Last verified: 2026-04-23 06:06:08 UTC Neutralised: 2026-04-23 05:06:02 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019d3688-9dc3-762f-9e29-e8a8cd688498/ Wayback Machine: https://web.archive.org/web/*/kra38r.ru crt.sh CT logs: https://crt.sh/?q=%25.kra38r.ru Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=kra38r.ru AlienVault OTX: https://otx.alienvault.com/indicator/domain/kra38r.ru URLhaus: https://urlhaus.abuse.ch/host/kra38r.ru/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-03-29 01:21:39 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] The domain kra38r.ru has been identified as an active credential theft site, posing an elevated risk to users who may interact with it. PhishDestroy detects ongoing malicious activity associated with this domain, which is currently classified under the generic phishing threat type with a focus on credential harvesting. The infrastructure and operational patterns indicate a deliberate effort to deceive users into surrendering sensitive login credentials under false pretenses. Immediate caution is advised when encountering this domain or any associated URLs. This domain was flagged by 2 of 95 VirusTotal security vendors, indicating limited but present detection of its malicious nature. It was registered through RU-CENTER-RU, resolves to the IP address 188.114.96.3, and was created on June 07, 2025. Despite its recent creation, the domain holds an SSL certificate issued by Google Trust Services, which may lend an air of legitimacy to unsuspecting users. The low detection rate on VirusTotal suggests that this domain may be newly operational or employing evasion techniques to avoid widespread blacklisting. The combination of a Russian registrar, recent creation date, and low blocklist presence contributes to its elevated risk profile. The current status of kra38r.ru remains active, with no signs of takedown or mitigation by hosting or security providers. Given its credential theft nature, users who have entered login credentials on this domain should immediately change passwords for the affected accounts and enable multi-factor authentication where available. Organizations are advised to block this domain and its associated IP at the network level to prevent further exposure. Additionally, users should report any interactions with this domain to relevant cybersecurity authorities or their IT departments. Proactive monitoring of account activity is strongly recommended to detect any unauthorized access or anomalous behavior stemming from credential compromise. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/kra38r.ru/ JSON API: https://api.destroy.tools/v1/check?domain=kra38r.ru Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io