krkn32[.]top
“Kraken Darknet Market | Оригинальное зеркало | Единственный официальный вход”
Résumé des preuves
Analysis of krkn32.top, observed as a brand‑impersonation site targeting the Kraken cryptocurrency exchange, was performed on 24 July 2026. The domain was registered on 21 February 2026 and resolves to the IP address 172.67.151.230, which belongs to Cloudflare, Inc. (AS13335) and is geolocated to the United States. The site’s SSL certificate is identified only as “WE1”, providing no additional validation of ownership. The page title returned from the server reads “Kraken Darknet Market | Оригинальное зеркало | Единственный официальный вход”, explicitly referencing a darknet market and using Russian language to suggest an “original mirror” and “the only official entry”. This title aligns with the declared scam type of a crypto‑related fraud.
Infrastructure analysis indicates that the domain is currently offline, and the phishing‑specific blocklist PhishDestroy has already taken the domain down. Independent security platforms have listed the domain on a single blocklist, and the Gridinsoft trust score is 0 out of 100, reflecting an extremely low reputation. VirusTotal scans show that three of ninety‑five antivirus engines flagged the domain, confirming the presence of malicious activity despite the limited detection count. The evidence points to a deliberate attempt to impersonate the Kraken brand and lure victims into a fake darknet marketplace, likely to harvest cryptocurrency credentials or funds.
However, the exact payload, credential‑stealing mechanisms, and any associated command‑and‑control infrastructure have not been disclosed in the available data, leaving the full attack chain uncertain. Defenders should add krkn32.top to their deny‑list for web‑filtering solutions, enforce TLS inspection to capture any hidden traffic, and monitor for connections to the Cloudflare IP 172.67.151.230 that may originate from internal hosts.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
10 sources externes surveillées Aucune correspondance
Analyse forensique
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif