kra-------43at[.]ru
“Kra43 — коллекции, маленькие находки и спокойные увлечения AT версия”
kra-------43at.ru — Contenu indisponible. Résumé des preuves: VirusTotal 5/95 (alphaMountain.ai, CyRadar, Fortinet, Gridinsoft, SOCRadar); Spamhaus DBL_SPAM; PhishDestroy score 65/100. Bureau d’enregistrement: REGRU-RU.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain kra-------43at.ru was registered on 19 Nov 2025 through the Russian registrar REGRU‑RU. It is hosted on the IP 193.105.134.21, which belongs to AS42237 w1n ltd and resolves to a location in Sweden. No TLS certificate is presented; HTTP connections are unencrypted. The authoritative nameservers are ns1.reg.ru and ns2.reg.ru, both typical of the .ru ccTLD registry.
The page title returned from the site reads “Kra43 — коллекции, маленькие находки и спокойные увлечения AT версия”, indicating a Russian‑language site but providing no indication of a legitimate service. Gridinsoft assigns a trust score of 0 / 100, and five of the ninety‑five VirusTotal scanners flagged the domain, confirming malicious behavior. The domain is listed on a single public blocklist and is actively blocked by the PhishDestroy service. The site has been taken offline at the time of analysis, but the historical artifacts suggest it was used for a generic phishing campaign.
Defenders should add the domain and its resolving IP address to deny‑list rules on perimeter firewalls and DNS filtering solutions. Continuous monitoring of the AS42237 block for any new hosts that resolve to the same IP range is advised, as threat actors often recycle infrastructure. Because the site is already flagged by multiple detection engines and carries a zero trust score, automated remediation can be safely applied. Analysts should retain the page title and registrar information for correlation with future phishing incidents that reference similar Russian‑language content.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif