kr-ab5-cc[.]ru
“Krab5 (cc) — технологические составы для промышленной сварки”
kr-ab5-cc.ru — Belum terverifikasi. Jenis penipuan: Generic Phishing. Ringkasan bukti: VirusTotal 5/91 (alphaMountain.ai, Bfore.Ai PreCrime, CRDF, Gridinsoft, SOCRadar); URLQuery 1 alert; CF Radar malicious; PhishDestroy score 71/100. Registrar: REGRU-RU.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Domain kr-ab5-cc.ru has been flagged by PhishDestroy as a crypto-drainer endpoint under active abuse. The domain is not impersonating a specific brand but is engineered to intercept and drain cryptocurrency wallet transactions via malicious JavaScript payloads. Threat intelligence indicates the domain is configured to serve a drainer kit that scans for Web3 wallet extensions (MetaMask, Phantom, Rabby, etc.) and silently replaces destination addresses at transaction signing time. No overt brand mimicry is observed, suggesting a generic but highly effective drainer deployment rather than a targeted phishing campaign.
Technical indicators are consistent with a newly stood-up operation: the domain was created on March 08, 2026 through REGRU-RU, resolving to IP 172.67.164.20. It acquired a Let’s Encrypt SSL certificate within hours of registration, enabling encrypted payload delivery. VirusTotal currently shows 2/95 detections and the domain remains unlisted by Google Safe Browsing (GSB) and all major public blocklists. WHOIS data is masked, a common tactic to delay takedown response. The seed identifier 200c89 confirms this is a tracked, evolving threat with no prior reputation, heightening the risk of rapid propagation across social media and phishing feeds.
As of this report, kr-ab5-cc.ru is active and unblocked. Immediate containment requires DNS sinkholing or browser policy blocks at the organizational level. Users should avoid visiting the domain and report any accidental access to wallet providers and security teams. Risk remains high until VT detections rise above 3/95 or GSB flags the domain, which historically occurs 24–72 hours after first abuse reports. Until then, the domain presents an active, low-signature threat with severe wallet-compromise potential. Disable Web3 extensions on untrusted networks and treat any transaction popup from this domain as hostile.
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | kr-ab5-cc.ru |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Teknologi · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of kr-ab5-cc.ru · checked Mar 28, 2026
Analisis Konfigurasi Situs
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive