portal[.]kraken19at-t[.]ru
“Торговый портал - Kraken Marketplace”
portal.kraken19at-t.ru — Contenu indisponible (HTTP 502). Usurpation de l'identité de la marque : Kraken; Type d'arnaque : Crypto Scam. Résumé des preuves: VirusTotal 9/95 (BitDefender, CRDF, CyRadar, Fortinet, G-Data); Spamhaus DBL_PHISH; PhishDestroy score 77/100. Bureau d’enregistrement: REGRU-RU.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of portal.kraken19at-t.ru shows a newly created (02 Dec 2025) domain registered through REGRU‑RU and hosted on nameservers ns1.hosting.reg.ru and ns2.hosting.reg.ru. The domain resolves to IP 31.31.196.214, which belongs to AS197695 owned by REG.RU and is geolocated in Russia. No SSL certificate is presented, indicating that the site was served only over HTTP.
The page title captured from the site, "Торговый портал – Kraken Marketplace," directly references the Kraken brand, confirming a brand‑impersonation tactic aimed at cryptocurrency users. VirusTotal scans have flagged the domain by nine of ninety‑five security vendors, and the domain appears on a single public blocklist. PhishDestroy has already taken the site offline and added it to its blocklist.
While the site is no longer reachable, the infrastructure—registrar, hosting IP, and lack of TLS—matches patterns observed in other crypto‑related impersonation campaigns. Defenders should continue to block the domain at network perimeter, update URL filtering rules to include the observed IP range, and monitor for future registrations that reuse the same registrar or nameserver configuration. Observers should also watch for replicas that may employ HTTPS or different subdomains while retaining the same brand‑targeted page title, as these could indicate a re‑deployment of the same campaign infrastructure.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif