# tr.kralbeti.co — SUSPICIOUS > tr.kralbeti.co hosts a crypto drainer that mimics real sites; 3/95 VirusTotal engines flag it since creation on April 7, 2026. ## Summary tr.kralbeti.co is a recently activated domain that poses an elevated risk as a generic phishing page designed to harvest cryptocurrency wallet credentials or seed phrases. Once a victim lands on the site, hidden JavaScript loads fake wallet-connect dialogs or login forms that closely resemble legitimate services. Behind the scenes, the page exfiltrates entered secrets to attacker-controlled servers, giving criminals direct control over victims’ crypto holdings. Security vendors have already begun flagging this domain; VirusTotal currently detects tr.kralbeti.co with only 3 out of 95 engines as of today. The domain was created on April 7, 2026, indicating it is extremely young and may have been stood up quickly for a short-lived campaign. It is registered through the bulletproof-friendly registrar Gname.com Pte. Ltd., a provider known for allowing high-risk registrations with minimal verification. The site also holds a valid Let’s Encrypt SSL certificate, which masquerades as legitimacy and fools some users into believing the connection is safe. When resolved, tr.kralbeti.co points to the IP address 45.90.16.68, a hosting range linked to previous malicious campaigns. If you visited tr.kralbeti.co and entered any wallet details, immediately revoke permissions in your wallet settings and move remaining funds to a newly generated address. Scan your device for malware with reputable antivirus tools such as Malwarebytes or Windows Defender Offline. Finally, monitor your browser extensions and reset passwords only after confirming the real site’s official domain matches PhishDestroy’s verified list. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-04-07 22:40:49 - Registrar: Gname.com Pte. Ltd. - IP: 45.90.16.68 ## Detection Status - VirusTotal: 3 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/tr.kralbeti.co - PhishDestroy: https://phishdestroy.io/domain/tr.kralbeti.co/ - LLM endpoint: https://phishdestroy.io/domain/tr.kralbeti.co/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/tr.kralbeti.co/ Last updated: 2026-04-09