kra46cc[.]kit-mc[.]ru
“kra46 - AT решения для автоматизации Minecraft серверов”
kra46cc.kit-mc.ru — Conteúdo indisponível. Representação da marca: Minecraft. Resumo das evidências: VirusTotal 3/95 (SOCRadar); PhishDestroy score 65/100. Registrador: REGRU-RU.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, kra46cc.kit-mc.ru, was registered on December 06, 2024, through REGRU-RU and impersonates Minecraft, targeting users seeking automation tools for Minecraft servers. The page title, 'kra46 - AT решения для автоматизации Minecraft серверов,' explicitly references Minecraft server automation solutions, indicating a likely attempt to distribute malicious software or harvest credentials under the guise of legitimate tools. As of July 25, 2026, the domain resolves to IP 193.105.134.30, hosted on AS42237 (w1n ltd) in Sweden, and is currently offline. Infrastructure analysis reveals no SSL certificate, and nameservers are ns1.regerey.com and ns2.regerey.com, both associated with the registrar.
Detection data is limited but indicative of malicious intent: 3 of 95 security vendors on VirusTotal flagged the domain, and it appears on one security blocklist, with PhishDestroy blocking it. Gridinsoft assigned a trust score of 0/100, reinforcing the elevated risk classification. The domain's creation date, registrar, and hosting provider align with patterns observed in brand impersonation campaigns, though the exact payload or infection vector remains unconfirmed due to the site's offline status. Defenders should treat this domain as malicious and prioritize blocking it at the DNS and network levels.
Review logs for connections to 193.105.134.30 or requests to kra46cc.kit-mc.ru, particularly from users accessing Minecraft-related resources. If the domain reactivates, capture HTTP headers, SSL certificates, and any downloaded files for further analysis. Given the impersonation of Minecraft, endpoint protection should scan for unauthorized modifications to game files or server configurations. No evidence links or additional context were provided, so reliance on the above indicators is advised.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo