Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
at-krab9[.]cc
“krab9.cc”
証拠の概要
PhishDestroy identifies at-krab9.cc as an active crypto-drainer domain registered on December 11, 2025 and currently resolving to IP 188.114.96.3. Security telemetry confirms this host serves credential-harvesting and wallet-draining payloads under the guise of fake job offers, classified as a generic phishing threat with elevated risk. The domain leverages social-engineering tactics to trick victims into connecting crypto wallets and signing malicious transactions that silently drain balances.
Technical indicators for this domain are conclusive: VirusTotal detection score is 3/95 security vendors; domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED; SSL certificate issued by Google Trust Services is active; first seen on December 11, 2025; and the IP address 188.114.96.3 is shared across multiple high-risk campaigns. Current blocklist coverage remains low, suggesting rapid propagation before widespread takedown.
At the time of analysis, at-krab9.cc remains active and is actively distributing malicious JavaScript payloads targeting cryptocurrency users. Immediate network block at DNS and IP levels is recommended, alongside user advisories to avoid job-offer links from unsolicited messages. Despite active takedown efforts, residual risk persists due to the domain’s recent registration and shared infrastructure, warranting continuous monitoring and proactive blocking.
送信済み証拠のスナップショット
- 送信日時
- 台帳レコード
- 1
- ケース ID
PD-20260328-2E4499- 取得ページのタイトル
- krab9.cc
- PDF 資料
- 証拠 PDF
証拠全文
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
ネットワークセキュリティインテリジェンス
脅威対応 Pipeline
ブロックリストの確認範囲
監視対象の外部情報源 10 件 · 保存スナップショット 2026年8月12日
保存済みの結果証拠
結果とテイクダウンの帰属
- 結果
live_content- 可用性
content_live- 原因
content_served- 確信度
- 90%
- 最初の観測
- 最新の観測
証拠の SHA-256 969b82e9703c
検出タイムライン
-
可用性
最初の保存値: 不明
993d00c35140 -
可用性
不明 → コンテンツ公開中
75a3c8d54253 -
可用性
コンテンツ公開中 → 不明
1d95ce071444 -
可用性
不明 → コンテンツ公開中
6eced5403a28 -
可用性
コンテンツ公開中 → 不明
7cebcfd4071c -
可用性
不明 → コンテンツ公開中
19df936802ad -
可用性
コンテンツ公開中 → 不明
ca255b61650a -
可用性
不明 → コンテンツ公開中
f151a577366d -
可用性
コンテンツ公開中 → 不明
d8f7d37d7f95 -
可用性
不明 → コンテンツ公開中
0f0043902756
すべて表示(4)
-
可用性
コンテンツ公開中 → 不明
afa49a2b04dd -
可用性
不明 → コンテンツ公開中
98a323abd272 -
可用性
コンテンツ公開中 → 不明
e70d6b0bd31a -
可用性
不明 → コンテンツ公開中
969b82e9703c
コミュニティ報告
コミュニティの 1 人が報告・初回確認 2026年3月28日
- 保存済み報告
- 1
- 報告された固有 URL
- 1
VirusTotalによる分析
サイトパフォーマンス分析
Google PageSpeed Insights — mobile performance audit of at-krab9.cc · checked Mar 29, 2026
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください