Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@ddos-guard.net.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
captcha[.]krab5[.]forum
“Captcha”
captcha.krab5.forum — असत्यापित. घोटाले का प्रकार: Generic Phishing. साक्ष्य सारांश: VirusTotal 11/91 (BitDefender, Chong Lua Dao, ESET, Fortinet, G-Data); PhishDestroy score 88/100. रजिस्ट्रार: Global Domain Group.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
This domain, captcha.krab5.forum, is flagged as an active high-risk phishing site impersonating a generic captcha or verification page, as indicated by its page title 'Captcha'. Registered on March 12, 2026, through Global Domain Group LLC, the domain remains operational and is currently resolving to IP 185.149.120.187, hosted under AS57724 (DDOS-GUARD LTD) in Russia. Infrastructure analysis reveals the use of Cloudflare nameservers (arushi.ns.cloudflare.com and viddy.ns.cloudflare.com) alongside DDoS-Guard protection, a common tactic to obscure hosting origins and evade takedowns. The site employs Node.js and Express, technologies frequently leveraged in phishing kits for dynamic content delivery. The SSL certificate is issued by Let's Encrypt (R13), providing HTTPS encryption but offering no assurance of legitimacy. As of July 12, 2026, the domain is blocked by at least one security vendor (PhishDestroy) and appears on one security blocklist. VirusTotal reports 15 detections out of 95 vendors, confirming malicious classification by a subset of engines. The HTTP status code 403 suggests the server is actively rejecting direct access, which may indicate cloaking behavior to evade automated analysis or restrict visibility to specific regions or user agents. Defenders should treat this domain as hostile infrastructure. Immediate actions include blocking resolution at the DNS level, adding the IP (185.149.120.187) and domain to firewall deny lists, and monitoring for related subdomains or newly registered lookalike domains under the krab5.forum namespace. The exact phishing lure or targeted brand is not yet confirmed, but the captcha-themed page title suggests an intent to harvest credentials or personal data under the guise of mandatory verification. Further analysis of network traffic or sandbox execution may clarify the payload or exfiltration endpoints.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
Registration: krab5.forum
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For the registrable domain krab5.forum behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 4 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comवायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of captcha.krab5.forum · checked Mar 12, 2026
साक्ष्य और बाहरी रिपोर्टें
PD-20260312-702FD9 Recipient: abuse@ddos-guard.net क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।