kra46-cc[.]farmaciaitali24[.]ru
“kra46 - круглосуточный CC-помощник в мире итальянской медицины”
kra46-cc.farmaciaitali24.ru — सामग्री अनुपलब्ध. घोटाले का प्रकार: Investment Scam. साक्ष्य सारांश: VirusTotal 13/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; PhishDestroy score 89/100. रजिस्ट्रार: REGRU-RU.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Analysis of kra46-cc.farmaciaitali24.ru shows a high‑risk investment phishing operation that has been taken offline as of the report date, July 23 2026. The domain was registered on December 11 2024 through the Russian registrar REGRU-RU and resolves to the IPv4 address 193.105.134.30, which is advertised as belonging to AS42237 w1n ltd in Sweden. No SSL certificate is present, indicating that the site served only HTTP content. The page title retrieved during earlier crawls reads "kra46 - круглосуточный CC‑помощник в мире итальянской медицины," suggesting a Russian‑language front that references the Italian medical sector, but the content has not been publicly released for further forensic review.
Reputation data shows the domain appears on a single security blocklist, PhishDestroy, and Google Safe Browsing flags it for social engineering. VirusTotal scans returned 13 detections out of 95 vendors, reinforcing the malicious classification. Gridinsoft assigned a trust score of zero out of one hundred, and the nameservers ns1.armadns.icu and ns2.armaddns.icu are associated with generic dynamic DNS services, a pattern often leveraged by threat actors to rapidly redeploy infrastructure. Given the offline status, immediate mitigation focuses on preventing re‑use of the hosting IP and the identified nameservers.
Defenders should add 193.105.134.30 to network blocklists, monitor for new domains registered with REGRU-RU that resolve to the same IP range, and enforce URL filtering for the domain and its parent zone. Continuous observation of PhishDestroy and Google Safe Browsing updates is advised to capture any re‑emergence of the site. The combination of multiple vendor detections, a zero trust score, and a targeted investment scam narrative warrants a high‑severity incident response and extended monitoring of related infrastructure.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।