kraken[.]krab2------cc[.]ru
“Кракен krab2 - платформа CC кэшбэка для онлайн-покупок”
kraken.krab2------cc.ru — Contenido no disponible. Suplantación de marca: Kraken; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 9/93 (ChainPatrol, BitDefender, CRDF, CyRadar, Fortinet); PhishDestroy score 77/100. Registrador: REGRU-RU.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of the domain kraken.krab2------cc.ru shows multiple indicators of malicious activity aligned with a brand‑impersonation campaign targeting the cryptocurrency exchange Kraken. The site was registered on 20 December 2025 through the Russian registrar REGRU‑RU, and its creation date places it well within the operational window of recent crypto‑related frauds. The page title captured in the intelligence, “Кракен krab2 - платформа CC кэшбэка для онлайн‑покупок”, references a cashback platform and includes the brand name “Кракен”, suggesting an attempt to lure users by mimicking legitimate Kraken services. The domain resolves to IP 91.236.116.210, which is assigned to AS42237 (w1n ltd) in Sweden, and the hosting provider is listed under the armadns.com nameservers.
No TLS certificate is present, meaning the site would have been served over plain HTTP, a common characteristic of low‑effort phishing or scam pages. Reputation checks reinforce the suspicion: Gridinsoft assigns a trust score of 0 / 100, the domain appears on one security blocklist, and PhishDestroy has actively blocked it. VirusTotal reports that 9 of 93 scanning engines flagged the domain, indicating a modest but notable detection rate. The threat classification in the intelligence labels the operation as a “Crypto Scam”, and the domain is explicitly noted to impersonate Kraken, confirming a targeted brand‑spoofing motive.
The current offline status limits immediate interaction, but the infrastructure—registration details, hosting, lack of encryption, and low trust rating—remains usable for future campaigns. Defensive recommendations include adding the domain and its resolving IP to outbound and inbound blocklists, monitoring any related sub‑domains under the same nameservers, and applying URL filtering rules for content that references Kraken or cryptocurrency cashback schemes. Continuous re‑scanning with multi‑engine services is advised to capture any updates to detection status.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.