kr-ab5-cc[.]ru
“Krab5 (cc) — технологические составы для промышленной сварки”
Riepilogo delle prove
Domain kr-ab5-cc.ru has been flagged by PhishDestroy as a crypto-drainer endpoint under active abuse. The domain is not impersonating a specific brand but is engineered to intercept and drain cryptocurrency wallet transactions via malicious JavaScript payloads. Threat intelligence indicates the domain is configured to serve a drainer kit that scans for Web3 wallet extensions (MetaMask, Phantom, Rabby, etc.) and silently replaces destination addresses at transaction signing time. No overt brand mimicry is observed, suggesting a generic but highly effective drainer deployment rather than a targeted phishing campaign.
Technical indicators are consistent with a newly stood-up operation: the domain was created on March 08, 2026 through REGRU-RU, resolving to IP 172.67.164.20. It acquired a Let’s Encrypt SSL certificate within hours of registration, enabling encrypted payload delivery. VirusTotal currently shows 2/95 detections and the domain remains unlisted by Google Safe Browsing (GSB) and all major public blocklists. WHOIS data is masked, a common tactic to delay takedown response. The seed identifier 200c89 confirms this is a tracked, evolving threat with no prior reputation, heightening the risk of rapid propagation across social media and phishing feeds.
As of this report, kr-ab5-cc.ru is active and unblocked. Immediate containment requires DNS sinkholing or browser policy blocks at the organizational level. Users should avoid visiting the domain and report any accidental access to wallet providers and security teams. Risk remains high until VT detections rise above 3/95 or GSB flags the domain, which historically occurs 24–72 hours after first abuse reports. Until then, the domain presents an active, low-signature threat with severe wallet-compromise potential. Disable Web3 extensions on untrusted networks and treat any transaction popup from this domain as hostile.
Data Coverage
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | kr-ab5-cc.ru |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of kr-ab5-cc.ru · checked Mar 28, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo