kraken[.]krab2---cc[.]ru
“Кракен krab2 - безопасная AT авторизация для покупателей”
Resumen de las pruebas
The domain kraken.krab2---cc.ru was registered on December 20, 2025 through the REGRU-RU registrar and resolves to the IPv4 address 91.236.116.210, an AS42237 host located in Sweden and operated by w1n ltd. The authoritative name servers for the zone are ns1.armadns.com and ns2.armadns.com. No TLS certificate was presented for the site, indicating that connections were unsecured. A scan on VirusTotal recorded 13 detections out of 93 security engines, and the domain appears on a single external blocklist.
Gridinsoft assigned a trust score of 0 out of 100, and the site was actively blocked by the PhishDestroy service. The page title retrieved during analysis reads "Кракен krab2 - безопасная AT авторизация для покупателей," which references the Kraken brand and describes a “secure AT authorization for buyers.” The campaign is classified as a crypto‑related scam that impersonates Kraken, consistent with the brand‑impersonation threat type and the elevated risk rating. As of the report date, July 23, 2026, the site is offline, preventing immediate interaction, but the infrastructure details remain valid for threat‑intel correlation.
Defensive teams should update network and endpoint filters to block connections to 91.236.116.210 and any subdomains of kraken.krab2---cc.ru, enforce DNS‑based allow‑list policies that exclude the known name servers, and monitor for future activity using the registrar and ASN indicators. Because the visual content of the landing page has not been captured, analysts should treat any unverified claims about page layout or credential capture mechanisms as uncertain until a live sample is observed. Continuous monitoring of VirusTotal, phishing‑filter feeds, and public reputation services is advised to detect any re‑hosting attempts that reuse the same domain name or hosting infrastructure.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 13/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.