kraken-zerkala-kr46cc[.]space
“Kraken: Официальный вход на сайт kra47.at kra47.cc и актуальное зеркало Кракен”
kraken-zerkala-kr46cc.space — Contenido no disponible. Suplantación de marca: Kraken; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 3/93 (ChainPatrol, alphaMountain.ai, SOCRadar); Google Safe Browsing flagged; PhishDestroy score 80/100. Registrador: NameSilo.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain kraken-zerkala-kr46cc.space was registered through NameSilo, LLC on 25 December 2025 and is presently taken offline. Infrastructure analysis shows it was hosted behind Cloudflare, using the authoritative nameservers kyree.ns.cloudflare.com and lucy.ns.cloudflare.com, and resolved to the IP address 188.114.97.3, which belongs to AS13335 Cloudflare, Inc., and is geolocated in the United States. No TLS certificate was observed, indicating an HTTP‑only service at the time of capture. The page title returned by the site reads “Kraken: Официальный вход на сайт kra47.at kra47.cc и актуальное зеркало Кракен”, directly referencing the legitimate cryptocurrency exchange Kraken and suggesting a login portal or mirror site. The known intelligence tags the activity as a crypto scam and classifies it as brand impersonation of Kraken.
Reputation checks reveal the domain appears on one security blocklist and is blocked by PhishDestroy. Google Safe Browsing flags the URL for social engineering, and three of ninety‑three VirusTotal scanners reported detections, reinforcing the malicious assessment. The Gridinsoft trust score for the domain is 0 out of 100, confirming an extremely low trust rating. No SSL certificate, combined with the absence of HTTPS, reduces the credibility of any credential‑collection attempt.
While the site is currently offline, the recorded infrastructure—Cloudflare front‑end, the specific IP range, and the Russian‑language page title—provides observable indicators that can be used for detection and mitigation. Defenders should continue to block the domain at DNS, proxy, and web‑filter layers, add the associated IP address to threat‑intel feeds, and monitor for any re‑appearance of the domain or similar naming patterns.
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.