Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
kraken2trfqodidvlh4aa337cpzfrhdlfldhve5nf-onion[.]com
“KRAKEN”
kraken2trfqodidvlh4aa337cpzfrhdlfldhve5nf-onion.com — असत्यापित. ब्रांड प्रतिरूपण: Kraken; घोटाले का प्रकार: Fake Exchange. साक्ष्य सारांश: VirusTotal 6/91 (alphaMountain.ai, Chong Lua Dao, Fortinet, Gridinsoft, SOCRadar); URLQuery 3 alerts; Spamhaus DBL_PHISH; PhishDestroy score 83/100. रजिस्ट्रार: NiceNIC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
This domain is a confirmed brand impersonation threat targeting Kraken, a major cryptocurrency exchange. The site mimics legitimate Kraken login or transaction pages to deceive users into entering credentials or transferring funds. Such impersonation domains are commonly used in crypto drainer attacks, where victims unknowingly authorize transactions that drain their wallets. The domain’s structure, including the use of an .onion address, suggests an attempt to evade detection and appear as an official darknet portal for Kraken services. Users who interact with this site risk financial loss, credential theft, and unauthorized access to their cryptocurrency holdings. Analysis indicates the domain was created on March 27, 2026, and is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. It resolves to the IP address 172.67.201.15, hosted on infrastructure associated with Cloudflare, Inc. in Canada. The domain is flagged by 8 out of 95 security vendors on VirusTotal, confirming its malicious nature. Additionally, it appears on one security blocklist and has been taken offline, though historical data remains a concern for retrospective threat analysis. The SSL certificate, issued by Let’s Encrypt (serial number E7), does not mitigate the risk, as malicious actors frequently use valid certificates to lend false legitimacy to phishing sites. Users who visited this domain should immediately revoke any active sessions or authorizations tied to Kraken or other cryptocurrency services. Change passwords for all crypto-related accounts, enable multi-factor authentication (MFA), and review transaction histories for unauthorized activity. If credentials or wallet details were entered, assume they are compromised and transfer remaining funds to a new, secure wallet. Monitor financial and account activity closely for signs of follow-up attacks, such as phishing emails or unauthorized login attempts. Organizations should update their blocklists to include this domain and its associated IP address to prevent future access. Given the elevated risk level, affected users are advised to report the incident to relevant cybersecurity authorities or their exchange’s fraud team for further investigation.
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | kraken2trfqodidvlh4aa337cpzfrhdlfldhve5nf-onion.com |
malicious | Sinkholed |
| OpenDNS | kraken2trfqodidvlh4aa337cpzfrhdlfldhve5nf-onion.com |
phishing | Phishing Block |
| Hagezi Threat Feed | kraken2trfqodidvlh4aa337cpzfrhdlfldhve5nf-onion.com |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-22 02:47:19 UTC
तकनीकें · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% विश्वासCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% विश्वासHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% विश्वासवायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of kraken2trfqodidvlh4aa337cpzfrhdlfldhve5nf-onion.com · checked Jun 26, 2026
साइट कॉन्फ़िगरेशन विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
PD-20260328-4EFCD4 Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।