kra------43--cc[.]ru
“Kra43 — ароматерапия, спокойствие и домашние ароматы CC версия”
kra------43--cc.ru — Contenido no disponible. Resumen de las pruebas: VirusTotal 15/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; Spamhaus DBL_SPAM; PhishDestroy score 95/100. Registrador: REGRU-RU.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis as of July 24, 2026 indicates that the domain kra------43--cc.ru is currently offline but exhibits multiple indicators of a high‑risk phishing infrastructure. The domain was registered on November 19, 2025 through the Russian registrar REGRU‑RU and uses the default reg.ru nameservers (ns1.reg.ru, ns2.reg.ru). DNS resolution points to IP 193.105.134.21, which is assigned to AS42237 operated by w1n ltd in Sweden. No TLS certificate is presented, meaning the site served HTTP only. The page title retrieved during the brief online window reads “Kra43 — ароматерапия, спокойствие и домашние ароматы CC версия”, suggesting a masquerade of an aromatherapy related service, though the content has not been further examined.
Threat intelligence feeds flag the domain on one security blocklist and Google Safe Browsing classifies it as a social‑engineering threat. VirusTotal scans show 15 of 95 AV engines flagging the domain, reinforcing the malicious assessment. The Gridinsoft trust score is 0/100, indicating no trust. PhishDestroy has already added the domain to its block list.
Given the combination of registrar characteristics, the hosting ASN, lack of encryption, and the multiple vendor detections, the infrastructure aligns with known generic phishing operations. However, the exact payload, credential‑stealing mechanisms, and target audience remain unverified because the site is no longer reachable. Defenders should block the domain at the DNS and proxy layers, monitor for any future re‑use of the IP address 193.105.134.21, and incorporate the observed indicators (page title, IP, ASN, registrar) into threat‑intel feeds. Continuous re‑evaluation is advised in case the domain becomes active again.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.