# PhishDestroy threat dossier — pos.krakenos.by ================================================================ Fetched: 2026-07-31 04:05:41 UTC Canonical: https://phishdestroy.io/domain/pos.krakenos.by/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Kraken ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, SOCRadar Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 87.232.65.92 (BY, Minsk) ASN: AS6697 Republican Unitary Telecommunication Enterprise Beltelecom Hosting org: Hosterby Cloud Registrar: Reliable Software, Ltd Nameservers: u1.hoster.by, u2.hoster.by Registered: 2026-04-15 Expires: 2027-04-15 Page title: KrakenOS Admin HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E7 Expires: 2026-08-20 Status: INVALID chain Fingerprint: ff9ad13820607eb233a580a78babaf0990a52e30023e76fbb2416ee27d4450a5 Subject Alternative Names (related infrastructure — often same operator): - admin.krakenos.by - analytics.krakenos.by - api.krakenos.by - app.krakenos.by - krakenos.by ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-15 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-20 19:48:40 UTC (by PhishDestroy tracker) First reported: 2026-07-20 18:05:33 UTC (abuse notice filed) Last verified: 2026-07-31 04:20:31 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f80a4-3aaf-7621-b285-1d8ac7607551/ URLQuery: https://urlquery.net/report/4c5bb42d-2a07-4c59-96e8-db6d62880d74 Wayback Machine: https://web.archive.org/web/*/pos.krakenos.by crt.sh CT logs: https://crt.sh/?q=%25.pos.krakenos.by Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=pos.krakenos.by AlienVault OTX: https://otx.alienvault.com/indicator/domain/pos.krakenos.by URLhaus: https://urlhaus.abuse.ch/host/pos.krakenos.by/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-20 19:48:53 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] pos.krakenos.by — Generic Phishing Report pos.krakenos.by is an active generic phishing infrastructure observed as of July 20 2026. The domain was registered on 15 April 2026 through the registrar Reliable Software, Ltd and is served by the authoritative name servers u1.hoster.by and u2.hoster.by. DNS resolution points to the single IPv4 address 87.232.65.92, which is the only host currently associated with the domain. The IP address is not listed as part of a known cloud provider range and has not been publicly associated with legitimate services. The domain appears on one security blocklist and has been explicitly blocked by the PhishDestroy phishing mitigation service. VirusTotal analysis shows that one out of ninety‑five scanned security vendors flagged the domain, indicating at least one detection for malicious activity. No additional public reputation scores, Safe Browsing checks, or open‑source intelligence (OTX) references were provided in the available data set. Because the domain is newly created, the short registration age (approximately three months) aligns with typical phishing campaign lifecycles that aim to exploit the trust window before detection mechanisms can fully propagate. No information about SSL/TLS configuration, HTTP response codes, page title, or landing‑page content is currently available, leaving the exact phishing lure and target brand unconfirmed. Defenders should treat pos.krakenos.by as high‑risk. Recommended actions include adding the domain and its resolving IP 87.232.65.92 to internal blocklists, monitoring DNS queries for the domain, and ensuring that outbound traffic to the associated IP is denied. Continuous re‑evaluation of the domain on VirusTotal and other multi‑engine scanners is advised to capture any changes in detection status. Network telemetry should be inspected for any recent connections to the IP address, and alerts should be generated for any successful TLS handshakes or HTTP requests targeting the domain. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260720-9DD94A TLS cert SHA-256: ff9ad13820607eb233a580a78babaf0990a52e30023e76fbb2416ee27d4450a5 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/pos.krakenos.by/ JSON API: https://api.destroy.tools/v1/check?domain=pos.krakenos.by Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,187 domains (84,173 alive under monitoring, 27,015 confirmed neutralized). Site: https://phishdestroy.io