kra46-at[.]fr65sakh[.]ru
“kra46 - AT портал дальневосточных новостей”
kra46-at.fr65sakh.ru — Konten tidak tersedia. Ringkasan bukti: VirusTotal 11/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker); PhishDestroy score 83/100. Registrar: REGRU-RU.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
The domain kra46-at.fr65sakh.ru was registered on 10 December 2024 through the REGRU‑RU registrar. DNS resolution points to the IPv4 address 193.105.134.30, which is announced by AS42237 (w1n ltd) and geolocated to Sweden. The authoritative name servers are ns1.armadns.com and ns2.armadns.com. No TLS certificate is presented, indicating that the site is served only over HTTP. The page title returned from the live host before it was taken offline reads “kra46 – AT портал дальневосточных новостей”, suggesting a Russian‑language news portal façade.
Gridinsoft assigns a trust score of 0 / 100, and the domain appears on a single external blocklist. VirusTotal analysis shows that 11 of 95 antivirus and URL‑reputation engines flagged the domain as malicious, reinforcing the suspicion of phishing activity. PhishDestroy has also listed the domain as blocked. The site’s current status is offline, limiting immediate observation of payload delivery or credential‑harvesting mechanisms.
Uncertainty remains around the specific phishing lure, the credential‑collection endpoint, and whether additional infrastructure (e.g., command‑and‑control servers) is associated with the same IP range. Defenders should add the domain and its IP address to inbound and outbound filtering rules, monitor DNS queries for the associated nameservers, and ensure that any HTTP traffic to the host is denied. Continuous re‑evaluation of the IP block (AS42237) is advised, as further malicious sites may be hosted there. Integration of the VirusTotal detection count and the PhishDestroy blocklist entry into threat‑intel platforms will improve detection of related campaigns.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive