krab1cc[.]shdamask[.]ru
krab1cc.shdamask.ru — Konten tidak tersedia (HTTP 502). Ringkasan bukti: VirusTotal 10/93 (BitDefender, CRDF, CyRadar, ESET, Fortinet); PhishDestroy score 80/100. Registrar: REGRU-RU.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
The domain krab1cc.shdamask.ru was observed as part of a generic phishing campaign and is currently offline. According to the intelligence, the domain resolves to the IPv4 address 91.236.116.210, which is advertised as belonging to AS42237 operated by w1n ltd in Sweden. No TLS certificate was presented during connection attempts, indicating that the site did not offer HTTPS protection. The host is listed on a single security blocklist and is actively blocked by the PhishDestroy service.
VirusTotal reports that ten out of ninety‑three scanning engines flagged the domain as malicious, reinforcing the suspicion of abusive activity. The registrar entry shows registration through REGRU‑RU, with the domain creation timestamp recorded as July 28, 2025. The domain employs the nameservers ns1.regerey.com and ns2.regerey.com, both of which resolve to the same provider and do not appear to be shared with known legitimate services. Gridinsoft assigns a trust score of 0 out of 100, reflecting a complete lack of reputation.
The combination of a low trust score, absence of TLS, and multiple detections suggests that the infrastructure was deliberately provisioned for phishing purposes and subsequently taken offline after detection. Defensive operators should continue to block the IP 91.236.116.210 and the associated nameserver hostnames, monitor for any re‑registration attempts of the same second‑level domain, and incorporate the domain and its IP into threat‑intelligence feeds. Ongoing observation of the registrar REGRU‑RU for similar registrations may reveal additional malicious domains. Because the site is no longer reachable, further content analysis is not possible, and any future activation would require fresh scanning to confirm the payload.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive