MALICIOUS — CRITICAL
Análisis de phishing y seguridad de krab14cc.cc
krab14cc[.]
The domain krab14cc.cc was registered on 12 December 2025 through NICENIC INTERNATIONAL GROUP CO., LIMITED and currently resolves to the IP address 172.67.130.27.
- VirusTotal
- 7/91
- Blocklists
- No stored match
- Disponibilidad
- Último activo conocido · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
krab14cc.cc — Último activo conocido (HTTP 200). Tipo de estafa: Generic Phishing. Resumen de las pruebas: VirusTotal 7/91 (alphaMountain.ai, Chong Lua Dao, CRDF, Forcepoint ThreatSeeker, Fortinet); Spamhaus DBL_PHISH; PhishDestroy score 81/100. Registrador: NiceNIC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Evidence Analysis
The domain krab14cc.cc was registered on 12 December 2025 through NICENIC INTERNATIONAL GROUP CO., LIMITED and currently resolves to the IP address 172.67.130.27. Authoritative nameservers casey.ns.cloudflare.com and sonia.ns.cloudflare.com place the domain behind a Cloudflare edge network. HTTP requests receive a 301 redirect, and the TLS certificate presented is issued by Google Trust Services under the WE1 root, confirming the use of a valid public certificate.
Infrastructure analysis shows reliance on Cloudflare services, as indicated by the detection of Cloudflare Browser Insights and support for HTTP/3. The IP address is allocated to Cloudflare, Inc. in Canada, matching a typical CDN‑based hosting pattern that aids anonymity and traffic amplification. The page title returned is “Krab14.cc”, identical to the domain name, suggesting minimal effort to conceal the landing page.
Reputation data reveals a Gridinsoft trust score of 0 out of 100 and placement on a single security blocklist. The domain is actively blocked by the PhishDestroy filter set, demonstrating prior detection of malicious activity. VirusTotal analysis shows that 7 of 95 scanned security engines flag the domain, reinforcing suspicion of abuse. The overall classification is “Generic Phishing”, consistent with credential‑harvesting tactics observed in similar campaigns.
Defenders should add krab14cc.cc to web‑filter and DNS‑sinkhole policies, ensure any redirects to the domain are intercepted, and monitor Cloudflare‑originated traffic for anomalous patterns. Because the site uses a valid TLS certificate, reliance on certificate validation alone will not prevent exposure; heuristic or reputation‑based controls are required. Continuous re‑scanning on platforms similar to VirusTotal is recommended to capture any changes in the domain’s detection profile.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cobertura de los datos12 recorded checks
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Latest Classified Outcome 2026-08-09 02:44:13 UTC
Tecnologías · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of krab14cc.cc · checked Mar 27, 2026
Análisis de la configuración del sitio
Datos y informes externosIndependent lookups and source reports
PD-20260326-430DE9 Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org Victim safety and official reportingImmediate actions and verified reporting channels
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.