arhinvest29[.]ru
“Kraken даркнет вход - все способы попасть на площадку”
arhinvest29.ru — 未検証. ブランドの偽装: Kraken; 詐欺タイプ: Crypto Scam. 証拠の概要: VirusTotal 12/91 (ADMINUSLabs, alphaMountain.ai, Bfore.Ai PreCrime, BitDefender, Chong Lua Dao); Google Safe Browsing flagged; PhishDestroy score 86/100. レジストラ: REGRU-RU.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
Analysis of arhinvest29.ru confirms it as a high-risk crypto scam domain impersonating the Kraken cryptocurrency exchange. The domain was registered on July 25, 2025, through REGRU-RU and is now offline, returning an HTTP 502 status. The page title, 'Kraken даркнет вход - все способы попасть на площадку,' explicitly targets Russian-speaking users with claims of darknet access to Kraken, a clear indicator of fraudulent intent. Google Safe Browsing flags this domain for social engineering, while PhishDestroy blocks it outright. Infrastructure analysis reveals hosting on 91.236.116.20, an IP address geolocated in Sweden (AS42237, w1n ltd), with DDoS-Guard and Yandex.Metrika technologies detected, suggesting an attempt to obscure traffic origins and monitor victim interactions.
Security vendor detections are mixed but indicative of malicious activity: 12 of 95 vendors on VirusTotal flagged the domain at the time of scanning, and it appears on at least one security blocklist. Scamadviser assigned a trust score of 45/100, while Gridinsoft rated it 0/100, reinforcing its classification as a scam. The SSL certificate, issued by Let's Encrypt (R12), is valid but does not mitigate the domain's fraudulent purpose. Nameservers ns1.armadns.com and ns2.armadns.com further link this infrastructure to other suspicious domains, though no direct ties to known phishing kits or campaigns are confirmed in the available data. Defenders should treat arhinvest29.ru as a confirmed threat targeting Kraken users.
Block the domain and its resolving IP (91.236.116.20) at the network level, and monitor for related domains using the same nameservers or hosting provider. While the site is currently offline, historical DNS records and SSL certificate transparency logs may reveal additional infrastructure. No evidence suggests this domain is part of a broader campaign, but its creation date and targeting align with trends in crypto-related phishing.
セキュリティシグナル
脅威対応 Pipeline
公開ブロックリスト登録状況
VirusTotalによる分析
アーカイブ済み証拠
サイトパフォーマンス分析
Google PageSpeed Insights — mobile performance audit of arhinvest29.ru · checked Mar 2, 2026
証拠および外部報告書
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください