krab3-zerkalo[.]online
“Инструкция 2026: вход на KRAKEN через актуальные ссылки и зеркала площадки”
krab3-zerkalo.online — Contenido no disponible. Suplantación de marca: Kraken; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 14/93 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker); Google Safe Browsing flagged; PhishDestroy score 92/100. Registrador: REGRU-RU.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of krab3-zerkalo.online indicates that the domain was registered on February 21, 2026 through the REGRU-RU registrar and is currently taken offline. The site presented a page titled "Инструкция 2026: вход на KRAKEN через актуальные ссылки и зеркала площадки," explicitly referencing the Kraken brand, confirming a brand‑impersonation campaign aimed at crypto users. Infrastructure inspection shows the domain resolving to IP address 104.21.25.44, an asset owned by Cloudflare, Inc. (AS13335) and located in the United States.
DNS resolution is handled by Cloudflare nameservers kayleigh.ns.cloudflare.com and lynn.ns.cloudflare.com, and no TLS certificate is provisioned for the domain, leaving communications unencrypted. Reputation data reveal that 14 of 93 VirusTotal‑registered security vendors have flagged the domain, and it appears on three independent security blocklists. Google Safe Browsing classifies the site as social engineering, while the Gridinsoft trust score is 0 out of 100, underscoring the high risk.
Additional defensive feeds have listed the domain in PhishDestroy, MetaMask, and SEAL blocklists, providing multiple points of detection for endpoint and web‑filter solutions. Given the confirmed brand targeting, the absence of SSL, and the low trust score, defenders should add the domain and its hosting IP to blocklists, monitor for any re‑deployment on alternative IP ranges, and ensure that user‑education campaigns address social‑engineering lures referencing Kraken. Continuous re‑scanning with multi‑vendor platforms is advised to capture any changes in detection status.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Inteligencia forense
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.