kr41cc[.]ru
Analyse phishing et sécurité de kr41cc.ru
“Kra41cc: Стильная и модная одежда для современных людей”
kr41cc.ru — Contenu indisponible (HTTP 502). Résumé des preuves: VirusTotal 5/95 (alphaMountain.ai, Bfore.Ai PreCrime, CyRadar, Gridinsoft, SOCRadar); PhishDestroy score 65/100. Bureau d’enregistrement: REGRU-RU.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of kr41cc.ru indicates that the site was registered on October 28, 2025 through the REGRU-RU registrar and uses the default reg.ru name servers (ns1.reg.ru, ns2.reg.ru). The domain resolves to IP address 92.255.111.71, which is assigned to AS9123 JSC TIMEWEB and geolocated to Russia. No SSL certificate is present, meaning any HTTP connections would be unencrypted. The page title retrieved before the site was taken offline reads "Kra41cc: Стильная и модная одежда для современных людей," suggesting a fashion‑oriented landing page, but no further page content has been captured.
Threat intelligence shows the domain appears in a single AlienVault OTX pulse and is listed on one security blocklist. PhishDestroy has already blocked the domain, and the Gridinsoft trust score is 0 out of 100, reflecting a very low confidence rating. VirusTotal scans report that five of ninety‑five antivirus engines flagged the domain, reinforcing the malicious classification. Current status is offline, so active probing is not possible, but the infrastructure remains reachable and could be re‑activated.
Defenders should continue to deny DNS resolution for kr41cc.ru, enforce HTTP/HTTPS inspection to catch any future traffic, and add the associated IP 92.255.111.71 to network‑level blocklists. Monitoring of the registrar (REGRU-RU) and the hosting ASN (AS9123) for new domains exhibiting similar characteristics is advised. Given the limited detection history, threat actors may be testing a new phishing campaign, so heightened vigilance for related URLs or copycat domains is warranted.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif