xn--kr45-rzb[.]cc
“Razer Kraken Blog - Обзоры и новости наушников”
xn--kr45-rzb.cc — Ammantato · raggiungibile (HTTP 502). Simulazione del marchio: Kraken; Tipo di truffa: Crypto Scam. Riepilogo delle prove: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 1 alert; Spamhaus DBL_PHISH; cloaking observed; PhishDestroy score 95/100. Registrar: NiceNIC.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Analysis as of July 25, 2026 indicates that the IDN domain xn--kr45-rzb.cc was registered on February 23, 2026 through NiceNIC International Group Co., Limited. The domain resolves to IP 101.99.75.96, which is attributed to AS45839 Shinjiru Technology Sdn Bhd in the Netherlands. DNS records list five authoritative name servers: ns0.1984.is, ns1.1984.is, ns1.1984hosting.com, ns2.1984.is, ns2.1984ho. The web service returns HTTP 403 and presents a TLS certificate issued by Let’s Encrypt (R12). Underlying technologies are identified as Ubuntu, Nginx, Node.js and the Express framework.
The page title returned by the server reads “Razer Kraken Blog - Обзоры и новости наушников”, linking the site to the Kraken brand. The Gridinsoft trust score is 0 / 100, indicating no trust. The domain appears on a single blocklist, PhishDestroy, and 16 of 93 VirusTotal scanners flagged it as malicious. The site is classified as a crypto‑related scam that impersonates Kraken, and the risk level is marked as elevated. The domain is currently taken offline; no further content can be retrieved beyond the HTTP 403 response.
Defenders should block DNS resolution to 101.99.75.96 and add xn--kr45-rzb.cc to URL filtering policies. Monitoring traffic to the listed name servers may reveal additional infrastructure reuse. Since the domain is already listed by PhishDestroy and multiple VirusTotal engines, adding it to internal blocklists is recommended. Organizations that use Kraken services should alert users to the possibility of credential harvesting attempts related to this domain. Continuous re‑evaluation is advised in case the domain is re‑activated.
Informazioni sulla sicurezza di rete Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | xn--kr45-rzb.cc |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Latest Classified Outcome 2026-08-14 03:42:17 UTC
Tecnologie · 4 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Analisi di VirusTotal
Prove archiviate
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of xn--kr45-rzb.cc · checked Mar 2, 2026
Dati e relazioni esterne
PD-20260223-AABE3F Recipient: abuse@shinjiru.com.my Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo