Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@trellian.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
kra11-cc[.]com
“kra11-cc.com”
kra11-cc.com — Não verificado. Tipo de golpe: Generic Phishing. Resumo das evidências: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 6 alerts; PhishDestroy score 95/100. Registrador: Virtualia.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Investigation reveals kra11-cc.com as a recently activated credential harvesting domain designed to mimic authentic cryptocurrency platforms, thereby luring users into divulging sensitive account credentials. The domain's nomenclature suggests an attempt to impersonate a legitimate Kraken service, potentially exploiting brand recognition to enhance credibility. No specific drainer kit signatures were detected in available telemetry, though the site's structure and lures align with known generic phishing templates targeting financial data. The domain was registered through Virtualia LLC and secured with a Let's Encrypt SSL certificate, which may be leveraged to foster a false sense of security among potential victims. Given the timing and tactics employed, this campaign likely aims to harvest login credentials for Kraken accounts, redirecting users to a spoofed authentication portal before exfiltrating entered data.
Technical indicators associated with this domain underscore its elevated risk profile. VirusTotal analysis confirms that only 1 out of 95 security vendors has flagged kra11-cc.com as malicious, highlighting a potential blind spot in detection mechanisms. The domain resolves to IP address 103.224.212.204, which may host additional malicious infrastructure or be part of a shared hosting environment. Registered on November 20, 2025, the domain is relatively new, suggesting opportunistic deployment rather than long-term persistence. It is currently not flagged by Google Safe Browsing (GSB), and public blocklist counts remain undetected, which could enable prolonged exposure. These indicators collectively point to a hastily assembled threat leveraging fresh infrastructure to evade early-stage detection.
The domain remains active as of the latest assessment, with no observed takedown or mitigation efforts in progress. Immediate defensive actions include adding kra11-cc.com and its resolved IP (103.224.212.204) to organizational blocklists and email security filters to prevent user exposure. Enhanced monitoring for associated infrastructure, such as newly registered domains from Virtualia LLC or connections to the same IP, is recommended to preemptively disrupt related campaigns. Despite its current low detection rate, the risk of user compromise remains elevated due to the domain's active status and the high-stakes nature of cryptocurrency account targeting. Users should exercise extreme caution when encountering this domain or any unsolicited links purporting to originate from Kraken services, verifying authenticity through official channels prior to credential submission.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | kra11-cc.com |
malicious | Sinkholed |
| DNS4EU | kra11-cc.com |
malicious | Sinkholed |
| Hagezi Threat Feed | ww17.kra11-cc.com |
malicious | Sinkholed |
| DNS4EU | ww17.kra11-cc.com |
malicious | Sinkholed |
| DigiCert UltraDNS | l.cdn-fileserver.com |
malicious | Sinkholed |
| DigiCert UltraDNS | s.cdn-fileserver.com |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias · 3 identified
Suite of cloud computing services running on Google infrastructure.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Content delivery network built on Google global edge infrastructure.
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
PD-20260329-BC96D0 Recipient: abuse@trellian.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo