kra18-at[.]cc
kra18-at.cc — Non vérifié. Type d'arnaque : Credential Phishing. Résumé des preuves: VirusTotal 16/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); Spamhaus DBL_PHISH; PhishDestroy score 95/100. Bureau d’enregistrement: NiceNIC.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, kra18-at.cc, is identified as a credential theft phishing operation targeting users through deceptive login portals. Analysis indicates no direct association with a specific brand or cryptocurrency drainer kit, but the infrastructure aligns with common credential harvesting tactics. The domain lacks SSL encryption, increasing the likelihood of intercepted data during transmission, and its design likely mimics legitimate authentication pages to trick victims into submitting sensitive information.
Technical indicators confirm elevated risk: the domain is flagged by 14 out of 95 security vendors on VirusTotal, appears on one security blocklist, and is currently blocked by at least one threat intelligence feed. Registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on March 29, 2026, the domain resolves to the IP address 95.85.236.107, hosted by MHost LLC in Germany. The creation date suggests either a typo-squatting attempt or pre-registration for future malicious campaigns, as the timestamp is set abnormally far in the future. No entries were found in Google Safe Browsing at the time of analysis, though this does not mitigate the domain's confirmed malicious status.
As of the latest assessment, kra18-at.cc has been taken offline, reducing immediate exposure risk. However, the infrastructure remains registered and could be reactivated or repurposed for similar attacks. Users who accessed the domain prior to its takedown should assume credential compromise and initiate password resets for any accounts entered on the site. Organizations are advised to monitor network logs for connections to 95.85.236.107 and implement DNS-based blocking of the domain to prevent potential re-emergence. No SSL certificate further underscores the domain's lack of legitimacy, reinforcing the need for heightened scrutiny of unencrypted login portals.
Renseignements sur la sécurité réseau Registrar context
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
Latest Classified Outcome 2026-08-14 02:44:19 UTC
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of kra18-at.cc · checked Mar 29, 2026
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif