Analysis of the domain krab61.ru shows a recently registered web address that is actively being used for malicious phishing operations. The domain was created on February 12, 2026 and is registered through the REGRU-RU registrar. It resolves to the IP address 172.67.203.47 and is served by Cloudflare, as indicated by the authoritative nameservers algin.ns.cloudflare.com and megan.ns.cloudflare.com. The hosting infrastructure is therefore protected by Cloudflare’s edge network, which can obscure the origin server but does not mitigate the malicious intent of the domain itself.
Security monitoring has placed krab61.ru on one public blocklist and the domain is currently blocked by the PhishDestroy service. VirusTotal scans have returned a single positive detection out of 91 security vendors, confirming that at least one vendor has identified the domain as malicious. No additional public threat‑intel sources such as OTX or Google Safe Browsing have published entries for this domain, and no SSL certificate details, HTTP response codes, page titles, or evidence URLs have been disclosed in the available intelligence. The limited detection footprint suggests that the campaign may be in an early stage or that the phishing site is being used sporadically to avoid broader exposure.
Defenders should add krab61.ru to internal blocklists, monitor DNS queries for the 172.67.203.47 address, and enforce outbound filtering for any traffic to this host. Continuous re‑scanning with multi‑vendor services is recommended to capture any future changes in detection status. Organizations that rely on email or web authentication should treat any credential requests originating from this domain as fraudulent and educate users to verify URLs before entering sensitive information.