Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 4. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

krk-zerkalo[.]ru

“Истёк срок регистрации домена”

Threat verdict Critical 76/100 evidence score
Availability Content unavailable Content was unavailable in the latest observation
VirusTotal detections: 4/94
OTX: 1 ref Jun 15, 2026
Evidence Summary
CRITICAL
Ref
8B9AC99B
Score
76/100

Analysis of the domain krk-zerkalo.ru shows a newly registered host that is actively serving HTTP content. The domain was created on March 28, 2026 and resolves to the IPv4 address 5.101.159.26. An HTTP GET request returns status code 200, indicating a live web server. The lack of an SSL certificate means all traffic is unencrypted, a common characteristic of credential‑harvesting sites. Infrastructure inspection reveals that the IP address is allocated to Beget Ltd in Russia, and the domain uses the provider’s default MX records (mx1.beget.com priority 10, mx2.beget.com priority 20). Gridinsoft assigns a trust score of 0 out of 100, effectively marking the host as untrusted. The domain appears on one public blocklist and has been flagged by the PhishDestroy filter, confirming that external defenses already consider it malicious. Threat intelligence sources corroborate the malicious classification. AlienVault OTX lists the domain in a single pulse, and VirusTotal reports that four out of ninety‑five scanning engines have identified it as malicious. Although the detection count is modest, the presence of any positive detections combined with the zero trust score and blocklist listing elevates the risk profile to high. The domain remains active as of the latest check on July 12, 2026. Defenders should treat krk-zerkalo.ru as a high‑confidence phishing indicator. Recommended actions include adding the domain and its resolving IP to network‑level deny lists, enforcing TLS inspection to capture any credential submissions, and updating email security gateways to block messages that reference the domain or its MX hosts. Continuous monitoring for new resolution changes or additional detections is advised to maintain situational awareness.

VirusTotal
VirusTotal
4 det.
OTX references
Age
5 mo
Observed status
Content unavailable
PhishDestroy
DestroyList
Listed
Data coverage VirusTotal 4 / 94 URLQuery not checked PhishStats not checked OTX 1 community reference CF Radar no data URLScan capture not submitted URLScan verdict verdict unavailable DNS blocks not checked TLS no certificate data WHOIS 5 mo old Screenshot not captured Redirect chain not probed

Threat Response Pipeline

Discovery
Checks
Reports
Availability
8/9

Public Blocklist Status

Domain Intelligence

Domain
Server / ASN nginx · AS198610 Beget LLC
IP Reputation abuse score 0/100 0 reports checked Jul 9, 2026
IP Address 5.101.159.26 RU
GeoRU St Petersburg, RU
NetworkAS198610 · Beget Ltd
RegistrationCreated Mar 28, 2026 (138d)
Time to First Unavailability 52 days
What we count Elapsed time from the first stored abuse report to the first observation that the content was unavailable. This does not establish the cause.
What each report contains Stored outgoing-report records may reference evidence available at the time, such as vendor verdicts, registration data, hosting details, classifications, or screenshots. This page does not infer the exact payload delivered, receipt, acknowledgement, or action by a recipient.
Technical detailsDNS, SSL SANs, timestamps
First DetectedJun 15, 2026
MX Records10 mx1.beget.com 20 mx2.beget.com
TLS Observationscanned Jul 19, 2026
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

4 / 94 security vendors flagged this domain
View on VT
Last analyzed

Evidence & External Reports

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/krk-zerkalo.ru"
  title="PhishDestroy threat report for krk-zerkalo.ru"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>