kra18f[.]cc
kra18f.cc — Não verificado. Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 14/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); PhishDestroy score 98/100. Registrador: Gname 251.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, kra18f.cc, is identified as a fake login portal designed to harvest user credentials through deceptive authentication interfaces. Analysis indicates the infrastructure mimics legitimate login pages, tricking visitors into submitting sensitive account details such as usernames, passwords, and potentially multi-factor authentication codes. The domain exhibits characteristics consistent with credential phishing campaigns, including the use of obfuscated scripts and cloned UI elements to evade detection by casual inspection. No evidence of crypto drainer functionality or direct financial exfiltration was observed, but credential theft remains the primary objective. Infrastructure analysis reveals the domain was registered on March 29, 2026, through Gname 251 Inc, a registrar frequently associated with high-risk domains. As of the latest assessment, kra18f.cc is flagged by 14 out of 95 security vendors on VirusTotal, indicating moderate to elevated detection rates. The domain appears on one security blocklist, specifically PhishDestroy, further corroborating its malicious classification. Current status shows the domain has been taken offline, though historical DNS records and cached content may still pose residual risks to users who interacted with it prior to deactivation. Users who visited kra18f.cc or entered credentials on any page hosted under this domain should assume their account details have been compromised. Immediate actions include resetting passwords for all potentially affected accounts, enabling multi-factor authentication where available, and monitoring for unauthorized access or transactions. System scans using updated security tools are recommended to detect any secondary payloads or persistent threats. Organizations should review logs for connections to this domain and assess whether internal credentials were exposed. Given the domain's offline status, further direct interaction is unlikely, but vigilance against follow-up phishing attempts or credential-stuffing attacks remains critical.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
Análise do VirusTotal
Análise da configuração do site
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo