kra-32[.]net
“Captcha”
kra-32.net — असत्यापित. घोटाले का प्रकार: Generic Phishing. साक्ष्य सारांश: VirusTotal 11/94 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); PhishDestroy score 83/100. रजिस्ट्रार: NiceNIC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
This domain, kra-32.net, is identified as a credential theft operation designed to deceive users into submitting sensitive authentication details through a fraudulent Captcha verification page. Analysis indicates the site employs social engineering tactics, presenting itself as a legitimate security checkpoint to trick visitors into entering usernames, passwords, or multi-factor authentication codes. The infrastructure is structured to capture and exfiltrate this data in real time, posing a direct risk to personal and corporate accounts, particularly those associated with financial or email services. Infrastructure analysis reveals multiple high-confidence indicators of malicious activity. The domain resolves to IP address 172.67.222.112 and was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on March 27, 2026, an unusually future-dated registration suggestive of automated abuse. It is flagged by 11 out of 95 security vendors on VirusTotal, appears on one security blocklist, and is assigned a trust score of 0/100. The site leverages Cloudflare for content delivery and HTTP/3 for transport, masking its true origin and complicating traceability. The page title, 'Captcha,' further supports the credential harvesting narrative, as this is a common disguise for phishing portals. Users who have visited kra-32.net or interacted with its content should take immediate corrective action. All credentials entered on the site must be considered compromised and should be reset across all platforms where reused. Enable multi-factor authentication on critical accounts and monitor for unauthorized access or transactions. Review browser history and installed extensions for anomalies, as credential theft sites may deploy tracking scripts or attempt to install malicious add-ons. Network administrators are advised to block the domain and associated IP at the perimeter and conduct internal scans for indicators of compromise, including connections to 172.67.222.112 or requests to kra-32.net. Given the elevated risk level and offline status, vigilance is required to prevent secondary infection or data exposure.
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-13 03:06:03 UTC
तकनीकें · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of kra-32.net · checked Jun 26, 2026
साक्ष्य और बाहरी रिपोर्टें
PD-20260328-4FAD23 Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।