kra46-cc[.]essens-city[.]ru
“kra46 - городская доставка еды с соблюдением CC стандартов качества”
kra46-cc.essens-city.ru — Conteúdo indisponível. Resumo das evidências: VirusTotal 10/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Fortinet); PhishDestroy score 80/100. Registrador: REGRU-RU.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of kra46-cc.essens-city.ru indicates that the domain was registered on 7 December 2024 through the Russian registrar REGRU‑RU. The authoritative nameservers ns1.regerey.com and ns2.regerey.com resolve the hostname to IPv4 address 193.105.134.30, which is announced by AS42237 operated by w1n ltd and geolocated to Sweden. No TLS certificate is presented; HTTP connections are therefore unencrypted. The site’s HTML title reads “kra46 – городской доставка еды с соблюдением CC стандартов качества”, suggesting an attempt to impersonate a food‑delivery service, but no further content has been captured. The domain is currently offline, having been taken down after detection.
It is listed on the PhishDestroy blocklist and appears on one additional security blocklist. VirusTotal scans show that 10 of 95 antivirus and URL‑reputation engines flagged the domain, reinforcing the suspicion of malicious use. Gridinsoft assigns a trust score of 0 out of 100, indicating a lack of reputation. No Safe Browsing or Open Threat Exchange entries are provided in the supplied intelligence. Defenders should treat the domain as malicious.
The presence of multiple vendor detections and a zero trust score, combined with the lack of TLS and the offline status after blocklisting, suggest the site was being used for a phishing campaign targeting users of Russian‑language food‑delivery services. Monitoring for DNS queries to the domain or its nameservers, as well as for outbound connections to the associated IP, is advisable. Blocking the IP address 193.105.134.30 and the domain at the perimeter firewall will prevent accidental access. Because the registrar is Russian‑based, threat‑intel teams may consider requesting additional details from REGRU‑RU or sharing the indicator with regional information‑sharing groups. Until further forensic artefacts are obtained, no legitimate purpose can be inferred, and any traffic matching this indicator should be flagged for investigation.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo