kra46-at[.]hram-tatiana[.]ru
“kra46 - AT культурно-исторический портал”
kra46-at.hram-tatiana.ru — सामग्री अनुपलब्ध. साक्ष्य सारांश: VirusTotal 1/95 (SOCRadar); PhishDestroy score 55/100. रजिस्ट्रार: REGRU-RU.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Analysis of the domain kra46-at.hram-tatiana.ru indicates it was a phishing site impersonating a cultural or historical portal, as suggested by its page title 'kra46 - AT культурно-исторический портал.' The domain was registered on December 10, 2024, through the registrar REGRU-RU. Infrastructure analysis reveals it resolved to the IP address 193.105.134.30, hosted on AS42237 (w1n ltd) in Sweden. The domain utilized nameservers ns1.armadns.icu and ns2.armadns.icu, a configuration often associated with malicious infrastructure. No SSL certificate was detected, increasing the likelihood of interception of unencrypted traffic.
At the time of assessment, the domain appeared on one security blocklist and was flagged by one of 95 security vendors on VirusTotal, specifically PhishDestroy. Gridinsoft assigned a trust score of 0/100, further indicating its malicious nature. The domain has since been taken offline, though residual DNS records or cached content may persist.
Defenders should monitor for related domains registered through REGRU-RU or resolving to the same IP range, particularly those using the armadns.icu nameservers. Given the limited detection data, additional scrutiny of the hosting provider AS42237 may be warranted to identify other potentially compromised or malicious domains. The exact content and phishing mechanics of the site remain unanalyzed, but the available evidence supports its classification as a generic phishing domain targeting users of cultural or historical portals.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।