kra48[.]cc
“Captcha”
Riepilogo delle prove
Analysis of kra48.cc shows a recently created domain that has been taken offline but exhibited several indicators of malicious use. The domain was registered on August 14, 2024 through CSL Computer Service Langenbach GmbH d/b/a joker.com and is delegated to the Cloudflare nameservers ganz.ns.cloudflare.com and naomi.ns.cloudflare.com. DNS resolution points to the IP address 172.67.69.159, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. No SSL/TLS certificate is presented for the host, meaning connections are unencrypted and vulnerable to interception.
The only visible HTTP artifact is the page title "Captcha," which suggests the site may have attempted to present a captcha challenge as part of a credential‑harvesting flow, though the exact content of the page has not been captured. Security‑vendor scanning on VirusTotal recorded three positive detections out of ninety‑five scanners, indicating that at least a small subset of vendors have identified the domain as suspicious. Independent scoring services reflect extreme risk: Gridinsoft assigns a trust score of 0 out of 100, and the domain appears on a single security blocklist. PhishDestroy has also listed kra48.cc as a blocked resource.
The current operational status is offline, which limits real‑time observation but does not eliminate residual risk for any cached or previously distributed links. Defenders should continue to block the domain at network perimeter devices, update URL filtering and DNS sinkhole entries, and monitor for any residual references in email or web traffic. Because the site’s exact phishing kit or targeted brand is not disclosed in the available intelligence, further investigation of historic snapshots or threat‑intel feeds is recommended to determine whether the captcha page was used to lure victims into submitting credentials or other sensitive data.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 10/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo