kra46-at[.]banketivanovo[.]ru
“kra46-at.banketivanovo.ru”
kra46-at.banketivanovo.ru — Contenu indisponible. Type d'arnaque : Banking Phishing. Résumé des preuves: VirusTotal 12/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Fortinet); Google Safe Browsing flagged; PhishDestroy score 86/100. Bureau d’enregistrement: REGRU-RU.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of kra46-at.banketivanovo.ru confirms its classification as a high-risk banking phishing domain, currently offline but previously active. The domain was registered on January 7, 2025, through REGRU-RU, a registrar frequently associated with malicious infrastructure. It resolved to 193.105.134.30, an IP address geolocated in Sweden and assigned to AS42237 (w1n ltd), a hosting provider commonly linked to phishing and fraudulent activities. No SSL certificate was detected, increasing the likelihood of interception or tampering during data transmission.
The domain was flagged by 12 of 95 security vendors on VirusTotal, indicating moderate but not universal detection. It appears on at least one security blocklist, specifically PhishDestroy, and is classified under Google Safe Browsing as a social engineering threat. The page title, matching the domain name (kra46-at.banketivanovo.ru), provides no additional brand-specific context, though the scam type is explicitly identified as banking phishing in available intelligence. Nameservers ns1.regerey.com and ns2.regerey.com further suggest ties to infrastructure previously observed in phishing campaigns.
Gridinsoft assigns the domain a trust score of 0/100, reinforcing its malicious classification. While the exact content of the phishing page remains unanalyzed, the combination of registrar, hosting provider, detection rates, and blocklist inclusion strongly supports its use in credential harvesting or financial fraud targeting Russian-speaking users. Defenders should treat this domain as compromised and prioritize blocking both the domain and its resolving IP (193.105.134.30) at the network level. Monitoring for re-registration or re-emergence under similar naming conventions (e.g., banketivanovo.ru variants) is recommended, as threat actors often reuse infrastructure patterns.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif