krab1-cc[.]mebel-prem[.]ru
“krab1 - AT магазин стильных аксессуаров для домашних питомцев”
krab1-cc.mebel-prem.ru — コンテンツが利用できません. 証拠の概要: VirusTotal 7/95 (alphaMountain.ai, CyRadar, Fortinet, Gridinsoft, Lionic); PhishDestroy score 71/100. レジストラ: REGRU-RU.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
Analysis of the domain krab1-cc.mebel-prem.ru indicates it was operational as a generic phishing site targeting online shoppers. The domain was registered on March 7, 2025, through REGRU-RU, a registrar frequently associated with abusive domains. Infrastructure analysis reveals the site resolved to the IP address 193.105.134.30, hosted under AS42237 (w1n ltd) in Sweden. No SSL certificate was present, increasing the risk of unencrypted data interception. The domain's nameservers, ns1.regerey.com and ns2.regerey.com, are consistent with patterns observed in other low-reputation hosting environments.
The page title, 'krab1 - AT магазин стильных аксессуаров для домашних питомцев' (translated: 'krab1 - AT store of stylish accessories for pets'), suggests the site impersonated a pet accessories retailer. However, no specific brand impersonation was confirmed in the available data. As of the report date, the domain appears on one security blocklist, and seven out of 95 security vendors on VirusTotal flagged it as malicious. GridinSoft assigned a trust score of 0/100, further corroborating its high-risk classification.
The domain has since been taken offline, though defenders should remain vigilant for re-registration or similar domains under the same registrar or hosting provider. Defenders are advised to block the domain and its associated IP (193.105.134.30) at the network level. Monitoring for newly registered domains under REGRU-RU or using the same nameservers (ns1.regerey.com, ns2.regerey.com) may help preemptively identify related threats. Given the lack of SSL and the hosting provider's history, organizations should prioritize user education on recognizing unsecured e-commerce sites, particularly those with non-standard domain structures or recent registration dates.
脅威対応 Pipeline
公開ブロックリスト登録状況
VirusTotalによる分析
証拠および外部報告書
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください