kra46-cc[.]filippok-langepas[.]ru
“kra46 - CC инновации в управлении проектами”
kra46-cc.filippok-langepas.ru — Contenuto non disponibile. Riepilogo delle prove: VirusTotal 14/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); Google Safe Browsing flagged; PhishDestroy score 92/100. Registrar: REGRU-RU.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Analysis of kra46-cc.filippok-langepas.ru shows a high‑risk credential harvesting infrastructure that was taken offline prior to the report date of July 24, 2026. The domain resolves to the public IPv4 address 193.105.134.30, which is registered to AS42237 (w1n ltd) in Sweden. Registration data indicates the domain was created on December 10, 2024 through the Russian registrar REGRU-RU. No TLS certificate is presented, meaning the site served only over HTTP, a common trait of low‑cost phishing deployments.
The page title returned by the host is "kra46 - CC инновации в управлении проектами," providing no direct indication of the targeted brand or service. Trust scoring from Gridinsoft assigns a zero out of one hundred, reflecting an extremely low reputation. The domain appears on a single security blocklist and is actively blocked by the PhishDestroy service. Google Safe Browsing classifies the URL as social engineering, and VirusTotal records 14 detections out of 95 scanned scanners, confirming malicious intent.
Nameserver delegation points to ns1.armadns.icu and ns2.armadns.icu, both of which are frequently associated with disposable or fast‑flux hosting. Current DNS queries show the domain as offline, suggesting the operators have withdrawn the site or are rotating infrastructure. Defenders should continue to block the domain at perimeter and DNS layers, monitor the associated IP 193.105.134.30 for any resurgence, and add the nameservers to watchlists for future abuse. Because the site lacks SSL and the page content is not publicly available, further forensic capture is not possible, and the primary mitigation remains proactive blocking and threat‑intel sharing.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi di VirusTotal
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo