# PhishDestroy threat dossier — krab--6----cc.ru ================================================================ Fetched: 2026-07-23 19:38:29 UTC Canonical: https://phishdestroy.io/domain/krab--6----cc.ru/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 53/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 3/94 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Gridinsoft URLQuery: -1 detections AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- Registered: 2026-03-28 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-03-28 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-03-28 06:30:07 UTC (by PhishDestroy tracker) First reported: 2026-06-15 00:27:29 UTC (abuse notice filed) Last verified: 2026-07-23 20:20:54 UTC Neutralised: 2026-04-23 13:24:16 UTC Current status: taken down (registrar suspended or DNS dead) ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-18 17:40:05 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] krab--6----cc.ru: Fake Brand Login Phish This domain, krab--6----cc.ru, was set up to trick people into handing over their login credentials by pretending to be a legitimate brand's sign-in page. The site would ask for usernames and passwords, then send that sensitive information straight to cybercriminals. Even though it is now offline, anyone who visited it before it was taken down could have unknowingly compromised their accounts. Security researchers identified this threat using multiple sources. The domain was created on March 28, 2026, and appears on one security blocklist. VirusTotal shows that 3 out of 95 security vendors flagged it as malicious, and it was also detected in one AlienVault OTX threat intelligence pulse. Its registrar was involved in the takedown, but the exact registrar isn't specified in the available data. If you or someone you know visited krab--6----cc.ru and entered any information, change those passwords immediately—especially for the brand it impersonated. Enable two-factor authentication wherever possible and monitor accounts for unusual activity. For a complete safety check, use PhishDestroy's verification tool to scan for any other risky sites you may have encountered. ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/krab--6----cc.ru/ JSON API: https://api.destroy.tools/v1/check?domain=krab--6----cc.ru Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,947 domains (58,596 alive under monitoring, 128,729 confirmed takedowns/dead). Site: https://phishdestroy.io