# www-kra46cc.ru — SUSPICIOUS > PhishDestroy identifies www-kra46cc.ru as a live PayPal credential phishing site detected by 0/95 VirusTotal engines. Check the full report. ## Summary PhishDestroy identifies www-kra46cc.ru as a live PayPal credential phishing domain currently under active investigation. This domain poses an immediate risk because it is designed to mimic a legitimate PayPal login page and trick users into entering their PayPal username and password. The site was registered on November 14, 2025, only days ago, and is already hosting a convincing replica aimed at harvesting sensitive financial credentials. The domain resolves to IP address 104.21.3.80 and uses a Google Trust Services SSL certificate, which may give users a false sense of security. The combination of a newly created domain, low detection rate (0 out of 95 security engines on VirusTotal), and a trusted SSL issuer makes this a particularly dangerous threat that can evade initial detection. We know this domain is dangerous because it was registered through DOMENUS-RU on November 14, 2025, and currently shows zero detections across 95 VirusTotal scanning engines as of the latest intelligence. These technical indicators—especially the zero-detection status and recent domain age—suggest this phishing site is newly deployed and actively targeting users. If you visited www-kra46cc.ru and entered any login details, immediately change your PayPal password and enable two-factor authentication. Scan your device with reputable antivirus software and monitor your financial accounts for unauthorized transactions. Avoid clicking any links from emails or messages related to this domain, and report the site to PayPal’s fraud team and your local cybercrime unit to help prevent further abuse. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2025-11-14 16:40:04 - Registrar: DOMENUS-RU - IP: 104.21.3.80 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/b75bf551-be7f-4b69-a13e-f6af48e8b61b - PhishDestroy: https://phishdestroy.io/domain/www-kra46cc.ru/ - LLM endpoint: https://phishdestroy.io/domain/www-kra46cc.ru/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/www-kra46cc.ru/ Last updated: 2026-03-28