online[.]kraken19at-t[.]ru
“Онлайн торговля - Kraken Marketplace”
online.kraken19at-t.ru — Conteúdo indisponível. Representação da marca: Kraken; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 9/95 (BitDefender, CRDF, CyRadar, Fortinet, G-Data); Spamhaus DBL_PHISH; PhishDestroy score 77/100. Registrador: REGRU-RU.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of online.kraken19at-t.ru shows a recently registered domain (created 2 December 2025) operated from a Russian IPv6 address 2a00:f940:2:2:1:1:0:172 belonging to ASN 197695, which is registered to REG.RU. The domain is hosted on nameservers ns1.hosting.reg.ru and ns2.hosting.reg.ru, both tied to the same registrar. No TLS certificate is presented, indicating the site does not serve HTTPS traffic. The only visible page title retrieved before takedown reads “Онлайн торговля - Kraken Marketplace”, directly referencing the legitimate Kraken brand.
Intelligence classifies the site as a crypto‑scam that impersonates Kraken, and it appears on a single external blocklist where PhishDestroy has already taken the domain offline. VirusTotal scans report nine detections out of ninety‑five scanners, confirming malicious activity. The lack of SSL, combined with the brand‑impersonating title and the detection footprint, suggests the domain was used to lure victims into fraudulent cryptocurrency transactions.
While the site is currently offline, its infrastructure components remain publicly resolvable and could be re‑activated. Defenders should continue to block the IP address and associated hostnames at network perimeter, add the domain to internal blacklist feeds, and monitor for any re‑registration attempts or similar patterns from the same registrar or name‑server set. Additional scrutiny of traffic targeting the IPv6 block and any future DNS queries for similar Kraken‑related terms is recommended to prevent recurrence.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo