kra102[.]cc
Riepilogo delle prove
This domain, kra102.cc, has been identified as a credential theft phishing operation targeting user login credentials through deceptive landing pages. As of the latest verification, the domain has been taken offline, though residual risks may persist through cached or mirrored instances. The threat actor likely employed social engineering tactics, such as fake login portals or fraudulent account verification prompts, to harvest sensitive authentication details from victims. Analysis of the domain's infrastructure reveals multiple indicators of malicious activity. The domain was registered on March 29, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-risk domains. It appears on one security blocklist, and nine of 95 VirusTotal security vendors have flagged it as malicious. No associated IP addresses or subdomains were provided in the initial intelligence, but the domain's creation date and registrar choice align with patterns observed in credential theft campaigns. The domain's offline status suggests possible takedown efforts or abandonment by the threat actor. Given the elevated risk level and historical activity, organizations and individuals are advised to implement the following mitigations: block the domain kra102.cc at the DNS and proxy levels to prevent accidental access; monitor network logs for any residual connections to the domain or its associated infrastructure; and conduct user awareness training to recognize credential theft tactics, such as unsolicited login prompts or urgent account verification requests. If the domain was previously accessed, affected accounts should be secured immediately through password resets and multi-factor authentication enforcement. Continuous monitoring for related domains or IP addresses is recommended, as threat actors often re-establish infrastructure under new identifiers.
Data Coverage
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 10/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
Analisi di VirusTotal
Analisi della configurazione del sito
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo