kra102[.]cc
証拠の概要
This domain, kra102.cc, has been identified as a credential theft phishing operation targeting user login credentials through deceptive landing pages. As of the latest verification, the domain has been taken offline, though residual risks may persist through cached or mirrored instances. The threat actor likely employed social engineering tactics, such as fake login portals or fraudulent account verification prompts, to harvest sensitive authentication details from victims. Analysis of the domain's infrastructure reveals multiple indicators of malicious activity. The domain was registered on March 29, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-risk domains. It appears on one security blocklist, and nine of 95 VirusTotal security vendors have flagged it as malicious. No associated IP addresses or subdomains were provided in the initial intelligence, but the domain's creation date and registrar choice align with patterns observed in credential theft campaigns. The domain's offline status suggests possible takedown efforts or abandonment by the threat actor. Given the elevated risk level and historical activity, organizations and individuals are advised to implement the following mitigations: block the domain kra102.cc at the DNS and proxy levels to prevent accidental access; monitor network logs for any residual connections to the domain or its associated infrastructure; and conduct user awareness training to recognize credential theft tactics, such as unsolicited login prompts or urgent account verification requests. If the domain was previously accessed, affected accounts should be secured immediately through password resets and multi-factor authentication enforcement. Continuous monitoring for related domains or IP addresses is recommended, as threat actors often re-establish infrastructure under new identifiers.
Data Coverage
ネットワークセキュリティインテリジェンス
脅威対応 Pipeline
ブロックリストの確認範囲
監視対象の外部情報源 10 件 · 保存スナップショット 2026年8月10日
保存済みキャプチャ
ドメイン・インテリジェンス
技術詳細DNS、TLS 名、タイムスタンプ
VirusTotalによる分析
サイト設定分析
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください