kra-------43at[.]ru
“Kra43 — коллекции, маленькие находки и спокойные увлечения AT версия”
kra-------43at.ru — सामग्री अनुपलब्ध. साक्ष्य सारांश: VirusTotal 5/95 (alphaMountain.ai, CyRadar, Fortinet, Gridinsoft, SOCRadar); Spamhaus DBL_SPAM; PhishDestroy score 65/100. रजिस्ट्रार: REGRU-RU.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain kra-------43at.ru was registered on 19 Nov 2025 through the Russian registrar REGRU‑RU. It is hosted on the IP 193.105.134.21, which belongs to AS42237 w1n ltd and resolves to a location in Sweden. No TLS certificate is presented; HTTP connections are unencrypted. The authoritative nameservers are ns1.reg.ru and ns2.reg.ru, both typical of the .ru ccTLD registry.
The page title returned from the site reads “Kra43 — коллекции, маленькие находки и спокойные увлечения AT версия”, indicating a Russian‑language site but providing no indication of a legitimate service. Gridinsoft assigns a trust score of 0 / 100, and five of the ninety‑five VirusTotal scanners flagged the domain, confirming malicious behavior. The domain is listed on a single public blocklist and is actively blocked by the PhishDestroy service. The site has been taken offline at the time of analysis, but the historical artifacts suggest it was used for a generic phishing campaign.
Defenders should add the domain and its resolving IP address to deny‑list rules on perimeter firewalls and DNS filtering solutions. Continuous monitoring of the AS42237 block for any new hosts that resolve to the same IP range is advised, as threat actors often recycle infrastructure. Because the site is already flagged by multiple detection engines and carries a zero trust score, automated remediation can be safely applied. Analysts should retain the page title and registrar information for correlation with future phishing incidents that reference similar Russian‑language content.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।