kra47-at[.]hsh72[.]ru
“krab1 - организатор AT приключений в стиле робинзонады”
kra47-at.hsh72.ru — Contenu indisponible. Résumé des preuves: VirusTotal 11/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); PhishDestroy score 83/100. Bureau d’enregistrement: REGRU-RU.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain is flagged as an elevated-risk phishing site targeting users seeking adventure tourism services, specifically impersonating an organizer of Robinson Crusoe-style expeditions. The threat type is credential harvesting and financial fraud, leveraging fake booking or registration pages to collect personal and payment data from victims under the guise of legitimate outdoor activity planning. Analysis indicates the domain kra47-at.hsh72.ru was registered on February 08, 2025, through REGRU-RU, a registrar frequently associated with malicious infrastructure. It resolves to IP address 193.105.134.30, hosted on AS42237 (w1n ltd) in Sweden, a network segment with a history of abuse. The domain lacks an SSL certificate, increasing exposure to man-in-the-middle interception. VirusTotal detection shows 11 out of 95 security vendors have flagged the domain as malicious, while it appears on one additional security blocklist. The page title, "krab1 - организатор AT приключений в стиле робинзонады," suggests a localized campaign targeting Russian-speaking users. Mitigation requires immediate blocking of the domain and its resolving IP (193.105.134.30) at the network perimeter. Security teams should update endpoint protection rules to detect and prevent access to kra47-at.hsh72.ru and monitor for related domains using similar naming patterns (e.g., "kraXX-at"). Users who may have interacted with the site should be instructed to reset credentials on any accounts used during the session, particularly if payment details were entered. Network logs should be reviewed for connections to 193.105.134.30 or domains registered via REGRU-RU within the same timeframe to identify potential compromise.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif