# PhishDestroy threat dossier — kraken-kra38.net ================================================================ Fetched: 2026-04-30 15:27:45 UTC Canonical: https://phishdestroy.io/domain/kraken-kra38.net/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Kraken Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: content_divergence) (score: 4/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 12/94 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Ermes, Google Safebrowsing URLQuery: 2 detections Public blocklists: listed on 3 independent blocklists Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.152.165 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Navicosoft Pty Ltd Nameservers: marvin.ns.cloudflare.com, sara.ns.cloudflare.com Registered: 2025-09-15 Page title: About Kraken | Buy, Sell & Crypto Market | Kra38 HTTP response: 403 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-06-09 Status: INVALID chain Fingerprint: 4388e76abd7969891145bb894c8efd061ed11c33e44e88d0d4be09a60b7df0af ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-09-15 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-25 15:07:16 UTC (by PhishDestroy tracker) First reported: 2026-04-25 12:08:44 UTC (abuse notice filed) Last verified: 2026-04-30 12:30:20 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019dc488-2373-71f8-a5bf-0cd159868cde/ URLQuery: https://urlquery.net/report/997a8a78-253c-4a4d-b18c-daf3d76fb012 Wayback Machine: https://web.archive.org/web/*/kraken-kra38.net crt.sh CT logs: https://crt.sh/?q=%25.kraken-kra38.net Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=kraken-kra38.net AlienVault OTX: https://otx.alienvault.com/indicator/domain/kraken-kra38.net URLhaus: https://urlhaus.abuse.ch/host/kraken-kra38.net/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-25 15:07:50 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies kraken-kra38.net as an active brand impersonation campaign targeting Kraken users. The domain mimics the legitimate Kraken exchange to harvest credentials or deploy crypto drainers, posing an elevated risk to visitors unfamiliar with impersonation tactics. Security telemetry confirms the domain was registered on September 15, 2025 through Navicosoft Pty Ltd and is already blocked by three security vendors, including SEAL and InversionDNS. According to VirusTotal, the domain shows 0 detections out of 95 engines as of the latest scan, indicating low AV coverage and high potential for undetected compromise. Google Safe Browsing flags the page under SOCIAL_ENGINEERING, and the domain resolves to IP 172.67.152.165 behind an SSL certificate issued by Google Trust Services, suggesting an attempt to appear legitimate while hosting malicious content. Users who visited kraken-kra38.net should immediately revoke any saved browser passwords, clear cached site data, and scan connected devices with updated endpoint protection. Avoid entering credentials or cryptocurrency wallet addresses on this domain. If funds or credentials were exposed, contact Kraken support through official channels and consider rotating passwords across unrelated services. Disable browser autofill for sensitive data and enable multi-factor authentication where possible to reduce exposure to future impersonation attacks. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260425-96995D Favicon MD5: 58473f32de2e00c70d83bb56c3a6830e TLS cert SHA-256: 4388e76abd7969891145bb894c8efd061ed11c33e44e88d0d4be09a60b7df0af ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/kraken-kra38.net/ JSON API: https://api.destroy.tools/v1/check?domain=kraken-kra38.net Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io