kra46[.]irbis-crimea[.]ru
“kra46 - экологический AT заповедник для редких видов”
kra46.irbis-crimea.ru — Contenu indisponible. Résumé des preuves: VirusTotal 5/95 (ADMINUSLabs, alphaMountain.ai, Fortinet, Gridinsoft, SOCRadar); PhishDestroy score 65/100. Bureau d’enregistrement: REGRU-RU.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, kra46.irbis-crimea.ru, is identified as a generic phishing site designed to deceive users by masquerading as an ecological reserve for rare species. The page title, 'kra46 - экологический AT заповедник для редких видов,' suggests an attempt to exploit trust in environmental or conservation organizations. Instead of providing legitimate information, the site likely aims to harvest sensitive user data, such as login credentials or personal details, through fraudulent forms or redirects. Phishing domains of this nature often employ social engineering tactics to manipulate victims into disclosing confidential information, which can then be used for identity theft, financial fraud, or further cyberattacks. Analysis indicates that this domain was registered on December 11, 2024, through the registrar REGRU-RU, a provider frequently associated with malicious infrastructure. VirusTotal detections reveal that 5 out of 95 security vendors have flagged this domain as malicious, a notable indicator of its suspicious nature. Additionally, the domain resolves to the IP address 193.105.134.30, which has been linked to other phishing or fraudulent activities. The domain appears on at least one security blocklist, and its Gridinsoft trust score of 0/100 further confirms its high-risk status. The combination of recent registration, low detection but notable flagging, and association with known malicious infrastructure underscores the elevated risk posed by this site. If a user has visited kra46.irbis-crimea.ru or interacted with its content, immediate action is required to mitigate potential risks. First, disconnect the device from the internet to prevent further data transmission to the malicious server. Run a full scan using updated antivirus or anti-malware software to detect and remove any potential infections. Users should also change passwords for any accounts accessed while the device was compromised, prioritizing those with sensitive or financial information. Monitor bank statements, credit reports, and online accounts for unauthorized activity, and consider enabling multi-factor authentication where available. If personal or financial data was entered on the site, report the incident to relevant authorities or financial institutions to prevent further exploitation. Finally, educate others about the risks of phishing sites, particularly those impersonating trusted organizations.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif