kra46cc[.]moscow-atelier-arbat[.]ru
“kra46 - AT-ателье модной одежды на Арбате”
kra46cc.moscow-atelier-arbat.ru — Conteúdo indisponível (HTTP 502). Resumo das evidências: VirusTotal 3/95 (Fortinet, SOCRadar, Webroot); PhishDestroy score 65/100. Registrador: REGRU-RU.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain kra46cc.moscow-atelier-arbat.ru was created on 07 December 2024 and is currently taken offline. Registration was performed through REGRU-RU and the authoritative name servers are ns1.regerey.com and ns2.regerey.com. The site resolves to the IPv4 address 193.105.134.30, which is allocated to AS42237 w1n ltd in Sweden. No TLS certificate is presented, indicating that the service operates without encryption.
The page title retrieved from the host reads "kra46 - AT-ателье модной одежды на Арбате", suggesting the site pretended to be associated with a fashion atelier on Moscow’s Arbat street, although the actual content has not been examined. Reputation scoring from Gridinsoft assigns a trust score of 0 out of 100, and the domain is listed on a single security blocklist. It is actively blocked by the PhishDestroy filtering service. VirusTotal analysis shows that three of ninety‑five scanners flagged the domain, reinforcing the suspicion of malicious intent.
While the offline status limits immediate interaction, the infrastructure details—particularly the IP address and registrar—provide actionable indicators for defenders. Recommended mitigation steps include adding the IP 193.105.134.30 to network deny lists, configuring DNS filters to block the domain, and monitoring for any future re‑registration attempts under the same registrar or name server configuration. Continuous observation of related threat intelligence feeds for the AS42237 prefix may also help detect correlated campaigns.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo