MALICIOUS — CRITICAL
kra---32[.]cc
The domain kra---32.cc is assessed as an elevated risk level due to its specific threat type of brand impersonation.
- VirusTotal
- 6/91
- Blocklists
- 2 · MetaMask, SEAL
- 可用性
- 最後に確認されたアクティブな状態 · HTTP 302
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@nicenic.net.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
kra---32.cc — 最後に確認されたアクティブな状態 (HTTP 302). ブランドの偽装: Kraken; 詐欺タイプ: Crypto Scam. 証拠の概要: VirusTotal 6/91 (alphaMountain.ai, Chong Lua Dao, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); URLQuery 4 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100. レジストラ: NiceNIC.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
Evidence Analysis
The domain kra---32.cc is assessed as an elevated risk level due to its specific threat type of brand impersonation. This domain impersonates the cryptocurrency exchange Kraken, posing a significant threat to users who may inadvertently interact with it, leading to potential financial loss or credential theft.
Analysis indicates that kra---32.cc was created on February 21, 2026, and is registered through NiceNIC International Group Co., Limited. The domain resolves to the IP address 172.67.202.28 and is currently offline, which may suggest a temporary takedown or abandonment. VirusTotal has flagged this domain with 7 out of 95 security vendors identifying it as malicious. Additionally, the domain appears on three security blocklists, further corroborating its suspicious nature. The SSL certificate for the domain is issued by Google Trust Services under the WE1 label, which may be an attempt to lend credibility to the impersonation. The combination of these indicators suggests that the domain was actively used for malicious purposes before being taken offline.
To mitigate the risks associated with brand impersonation, users are advised to verify the URLs of websites they visit, especially those purporting to represent legitimate brands like Kraken. Multi-factor authentication (MFA) should be enabled on all accounts to add an additional layer of security. In case of any doubt, users should contact the official customer support of the brand to confirm the legitimacy of the website or any communications received. Security software and browser extensions that can detect and block known malicious domains should also be utilized.
データの網羅性12 recorded checks
ネットワークセキュリティインテリジェンス Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | krk49.at |
malicious | Sinkholed |
| Quad9 DNS | krk49.at |
malicious | Sinkholed |
| DNS4EU | krk49.at |
malicious | Sinkholed |
| Quad9 DNS | kra---32.cc |
malicious | Sinkholed |
脅威対応 Pipeline
公開ブロックリスト登録状況
Latest Classified Outcome 2026-08-09 02:44:03 UTC
使用技術 · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotalによる分析
アーカイブ済み証拠
証拠および外部報告書Independent lookups and source reports
PD-20260204-8437CA Recipient: abuse@nicenic.net Victim safety and official reportingImmediate actions and verified reporting channels
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。