ww16[.]kraken10[.]co
“kraken10.co”
ww16.kraken10.co — クローク済み · 到達可能 (HTTP 502). ブランドの偽装: Kraken; 詐欺タイプ: Brand Impersonation. 証拠の概要: VirusTotal 0/94; cloaking observed; PhishDestroy score 80/100. レジストラ: Above.com Pty.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
PhishDestroy identifies ww16.kraken10.co as an active brand impersonation threat under investigation. This domain mimics Kraken, a prominent cryptocurrency exchange, with the intent to deceive users into surrendering sensitive credentials or digital assets. While no drainer kit has been directly observed at this stage, the domain’s structure and naming convention strongly suggest a phishing operation targeting Kraken’s user base. The threat actor likely leverages social engineering tactics, such as spoofed emails or fake support links, to lure victims to the fraudulent site.
This domain was flagged with the following technical indicators: it currently shows 0 out of 95 detections on VirusTotal, indicating a low immediate detection rate. Registered through Above.com Pty Ltd., the domain resolves to IP address 64.190.63.136. The SSL certificate was issued by DigiCert Inc, and the domain was created on May 24, 2025. As of the latest assessment, Google Safe Browsing (GSB) has not flagged the domain, and no blocklist entries have been recorded. These attributes suggest a recently deployed and potentially low-profile threat.
The domain remains active and is considered a high-priority investigative target due to its clear intent to impersonate a well-known brand. No active takedown efforts have been confirmed, leaving the risk of continued user exposure elevated. Users are strongly advised to avoid accessing ww16.kraken10.co or any subpages under kraken10.co. Organizations should add the domain and its associated IP to network blocklists and monitor for inbound or outbound connections. Additionally, users of Kraken or similar services should verify URLs carefully, enable multi-factor authentication, and report suspicious communications. The remaining risk is assessed as moderate-to-high pending further forensic analysis and potential takedown actions.
ネットワークセキュリティインテリジェンス
脅威対応 Pipeline
公開ブロックリスト登録状況
VirusTotalによる分析
証拠および外部報告書
PD-20260328-6098D9 Recipient: abuse@above.com このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください