kra47-cc[.]faberlik-vg[.]ru
“krab1 - инновационные CC материалы для строительной отрасли”
kra47-cc.faberlik-vg.ru — Contenido no disponible. Resumen de las pruebas: VirusTotal 13/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); Google Safe Browsing flagged; PhishDestroy score 89/100. Registrador: REGRU-RU.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain kra47-cc.faberlik-vg.ru has been identified as a high-risk phishing infrastructure specifically designed to harvest credit card credentials. Analysis indicates this domain does not represent legitimate construction supply services but instead mimics industry terminology to deceive targets into submitting financial data. The page title 'krab1 - инновационные CC материалы для строительной отрасли' explicitly references credit card materials, confirming its fraudulent financial focus. Current status shows the domain has been taken offline, though residual risk remains for previously compromised systems. Infrastructure analysis reveals multiple technical indicators of malicious activity. The domain was registered on March 02, 2025 through REGRU-RU and resolves to IP address 193.105.134.30, hosted on AS42237 (w1n ltd) in Sweden. Security vendors have flagged this domain with 13 detections out of 95 on VirusTotal, while Google Safe Browsing classifies it as phishing. The domain appears on one security blocklist and operates without SSL certification, further reducing its legitimacy. Creation date proximity to detection suggests rapid deployment for malicious purposes. Organizations should treat this domain as an active threat vector. Immediate actions include blocking the domain and IP 193.105.134.30 at perimeter security devices, adding detection rules for the page title pattern, and monitoring for connections to AS42237 infrastructure. Financial institutions should flag any transactions originating from this domain's collection period (March 2025 onward) for enhanced fraud review. Users who accessed the domain should initiate credit monitoring and consider card replacement, as the absence of SSL indicates credentials were likely transmitted in cleartext. The domain's recent creation and specialized targeting suggest potential for similar campaigns from the same threat actor.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.