kraken[.]krab2------cc[.]ru
“Кракен krab2 - платформа CC кэшбэка для онлайн-покупок”
kraken.krab2------cc.ru — Contenu indisponible. Usurpation de l'identité de la marque : Kraken; Type d'arnaque : Crypto Scam. Résumé des preuves: VirusTotal 9/93 (ChainPatrol, BitDefender, CRDF, CyRadar, Fortinet); PhishDestroy score 77/100. Bureau d’enregistrement: REGRU-RU.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of the domain kraken.krab2------cc.ru shows multiple indicators of malicious activity aligned with a brand‑impersonation campaign targeting the cryptocurrency exchange Kraken. The site was registered on 20 December 2025 through the Russian registrar REGRU‑RU, and its creation date places it well within the operational window of recent crypto‑related frauds. The page title captured in the intelligence, “Кракен krab2 - платформа CC кэшбэка для онлайн‑покупок”, references a cashback platform and includes the brand name “Кракен”, suggesting an attempt to lure users by mimicking legitimate Kraken services. The domain resolves to IP 91.236.116.210, which is assigned to AS42237 (w1n ltd) in Sweden, and the hosting provider is listed under the armadns.com nameservers.
No TLS certificate is present, meaning the site would have been served over plain HTTP, a common characteristic of low‑effort phishing or scam pages. Reputation checks reinforce the suspicion: Gridinsoft assigns a trust score of 0 / 100, the domain appears on one security blocklist, and PhishDestroy has actively blocked it. VirusTotal reports that 9 of 93 scanning engines flagged the domain, indicating a modest but notable detection rate. The threat classification in the intelligence labels the operation as a “Crypto Scam”, and the domain is explicitly noted to impersonate Kraken, confirming a targeted brand‑spoofing motive.
The current offline status limits immediate interaction, but the infrastructure—registration details, hosting, lack of encryption, and low trust rating—remains usable for future campaigns. Defensive recommendations include adding the domain and its resolving IP to outbound and inbound blocklists, monitoring any related sub‑domains under the same nameservers, and applying URL filtering rules for content that references Kraken or cryptocurrency cashback schemes. Continuous re‑scanning with multi‑engine services is advised to capture any updates to detection status.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif