kra47-cc[.]faberlik-vg[.]ru
“krab1 - инновационные CC материалы для строительной отрасли”
kra47-cc.faberlik-vg.ru — Contenu indisponible. Résumé des preuves: VirusTotal 13/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); Google Safe Browsing flagged; PhishDestroy score 89/100. Bureau d’enregistrement: REGRU-RU.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain kra47-cc.faberlik-vg.ru has been identified as a high-risk phishing infrastructure specifically designed to harvest credit card credentials. Analysis indicates this domain does not represent legitimate construction supply services but instead mimics industry terminology to deceive targets into submitting financial data. The page title 'krab1 - инновационные CC материалы для строительной отрасли' explicitly references credit card materials, confirming its fraudulent financial focus. Current status shows the domain has been taken offline, though residual risk remains for previously compromised systems. Infrastructure analysis reveals multiple technical indicators of malicious activity. The domain was registered on March 02, 2025 through REGRU-RU and resolves to IP address 193.105.134.30, hosted on AS42237 (w1n ltd) in Sweden. Security vendors have flagged this domain with 13 detections out of 95 on VirusTotal, while Google Safe Browsing classifies it as phishing. The domain appears on one security blocklist and operates without SSL certification, further reducing its legitimacy. Creation date proximity to detection suggests rapid deployment for malicious purposes. Organizations should treat this domain as an active threat vector. Immediate actions include blocking the domain and IP 193.105.134.30 at perimeter security devices, adding detection rules for the page title pattern, and monitoring for connections to AS42237 infrastructure. Financial institutions should flag any transactions originating from this domain's collection period (March 2025 onward) for enhanced fraud review. Users who accessed the domain should initiate credit monitoring and consider card replacement, as the absence of SSL indicates credentials were likely transmitted in cleartext. The domain's recent creation and specialized targeting suggest potential for similar campaigns from the same threat actor.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif