kra--34--cc[.]top
“Welcome to nginx!”
kra--34--cc.top — Konten tidak tersedia. Ringkasan bukti: VirusTotal 9/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLQuery 2 alerts; Spamhaus DBL_SPAM; PhishDestroy score 83/100. Registrar: 耐思尼克国际集团有限公司.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
The domain kra--34--cc.top has been identified as a fake web server phishing site designed to deceive users by impersonating legitimate server infrastructure. Analysis indicates the domain is not associated with any specific brand impersonation but instead presents a generic nginx welcome page, a common tactic to evade initial suspicion while preparing for malicious activity. The domain is currently offline, though its prior activity and infrastructure warrant close scrutiny. Infrastructure analysis reveals the domain was flagged by 9 of 95 security vendors on VirusTotal, indicating a high likelihood of malicious intent. It is registered through 耐思尼克国际集团有限公司, a registrar frequently associated with high-risk domains, and resolves to the IP address 193.105.134.22, hosted by w1n ltd in Sweden. The domain was created on March 29, 2026, suggesting either a typo-squatting attempt or a preemptive registration for future malicious campaigns. It appears on one security blocklist and is associated with an SSL certificate issued to Internet Widgits Pty Ltd, a common placeholder name used in automated certificate generation for malicious domains. The combination of these indicators—low vendor detection diversity, suspicious registrar, and generic SSL certificate—elevates the risk profile. Current status confirms the domain has been taken offline, likely due to detection and mitigation efforts. However, the infrastructure remains a potential threat vector for future campaigns. Organizations and users are advised to block the domain and its associated IP address at the network level. Security teams should monitor for similar domains registered through the same registrar or resolving to the same IP range. Users who may have interacted with the domain should verify their systems for unauthorized access or data exposure, particularly if credentials were entered. Proactive measures, such as implementing domain reputation checks and enforcing strict SSL certificate validation, are recommended to mitigate risks from similar threats.
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | kra--34--cc.top |
malicious | Sinkholed |
| DNS4EU | kra--34--cc.top |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive