kra-40--at[.]cc
“KRA - всегда свежие продукты в нашем маркете”
Riepilogo delle prove
Analysis of the domain kra-40--at.cc indicates it is a fraudulent phishing site targeting Russian-speaking users under the guise of a grocery marketplace. The domain was registered on February 21, 2026, through NiceNIC International Group Co., Limited, and is currently offline as of July 23, 2026. Infrastructure analysis reveals the domain resolved to the IP address 193.124.112.251, hosted on AS48347 (JSC Mediasoft ekspert) in Russia. The page title, 'KRA - всегда свежие продукты в нашем маркете,' suggests an attempt to impersonate a legitimate grocery or retail service, though no specific brand is confirmed in the available data.
Security vendors have flagged this domain, with 15 out of 95 engines on VirusTotal detecting malicious activity. The domain appears on at least one security blocklist and is blocked by PhishDestroy, further supporting its classification as a phishing threat. No SSL certificate was present, which is atypical for legitimate e-commerce sites and increases the likelihood of credential interception. The use of DNSPod nameservers (a.dnspod.com, b.dnspod.com, c.dnspod.com) is consistent with domains used in phishing campaigns, though not inherently malicious on its own.
While the domain is currently offline, defenders should treat it as a confirmed phishing threat. Organizations are advised to block the domain and its associated IP (193.124.112.251) at the network level, update endpoint protection signatures, and monitor for any re-emergence or related infrastructure. The lack of SSL and the domain's recent creation, combined with detection by multiple security vendors, provide sufficient evidence to classify this as an elevated-risk phishing operation. No additional details about the phishing kit or exact victim targeting are available at this time.
Istantanea delle prove inviate
- Inviato
- Voci del registro
- 1
- ID del caso
PD-20260212-2CF25F- Artefatto PDF
- Prova in PDF
Testo completo delle prove
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 13/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo