kra46-cc[.]farmaciaitali24[.]ru
“kra46 - круглосуточный CC-помощник в мире итальянской медицины”
kra46-cc.farmaciaitali24.ru — Contenido no disponible. Tipo de estafa: Investment Scam. Resumen de las pruebas: VirusTotal 13/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; PhishDestroy score 89/100. Registrador: REGRU-RU.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of kra46-cc.farmaciaitali24.ru shows a high‑risk investment phishing operation that has been taken offline as of the report date, July 23 2026. The domain was registered on December 11 2024 through the Russian registrar REGRU-RU and resolves to the IPv4 address 193.105.134.30, which is advertised as belonging to AS42237 w1n ltd in Sweden. No SSL certificate is present, indicating that the site served only HTTP content. The page title retrieved during earlier crawls reads "kra46 - круглосуточный CC‑помощник в мире итальянской медицины," suggesting a Russian‑language front that references the Italian medical sector, but the content has not been publicly released for further forensic review.
Reputation data shows the domain appears on a single security blocklist, PhishDestroy, and Google Safe Browsing flags it for social engineering. VirusTotal scans returned 13 detections out of 95 vendors, reinforcing the malicious classification. Gridinsoft assigned a trust score of zero out of one hundred, and the nameservers ns1.armadns.icu and ns2.armaddns.icu are associated with generic dynamic DNS services, a pattern often leveraged by threat actors to rapidly redeploy infrastructure. Given the offline status, immediate mitigation focuses on preventing re‑use of the hosting IP and the identified nameservers.
Defenders should add 193.105.134.30 to network blocklists, monitor for new domains registered with REGRU-RU that resolve to the same IP range, and enforce URL filtering for the domain and its parent zone. Continuous observation of PhishDestroy and Google Safe Browsing updates is advised to capture any re‑emergence of the site. The combination of multiple vendor detections, a zero trust score, and a targeted investment scam narrative warrants a high‑severity incident response and extended monitoring of related infrastructure.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.