test[.]contactango[.]ru
“Зеркало Кракен казино ❤️ Официальный сайт Kraken casino 2025”
Detecção armazenada
Alerta de cloaking
- Tipo de cloaking
content_divergence- Pontuação de cloaking
- 2/6
Resumo das evidências
On July 25, 2026 analysts observed the domain test.contactango.ru hosting a brand‑impersonation campaign that targets the cryptocurrency exchange Kraken. The site was registered on February 21, 2026 and resolves to the IPv4 address 95.129.234.102, which belongs to the AS57724 DDOS‑GUARD LTD network in Russia. An SSL certificate issued by Let’s Encrypt (R12) is present, but the HTTP response returned a 502 status code at the time of collection, indicating a server‑side error or intentional takedown. The page title retrieved from the live endpoint reads “Зеркало Кракен казино ❤️ Официальный сайт Kraken casino 2025,” confirming the use of Kraken’s brand in a gambling‑oriented context.
Automated analysis identified a WordPress stack with MySQL, PHP, Yoast SEO, Unpkg, jQuery and jQuery Migrate, as well as DDoS‑Guard services, suggesting a typical compromised CMS deployment. Malware and phishing detection services flagged the domain: VirusTotal recorded a single positive detection out of 93 scanners, and the domain appears on one external security blocklist, where it has been actively blocked by PhishDestroy. The site is also classified under the “Gambler Scam” phishing kit, and the overall trust score from Gridinsoft is 0 out of 100, reinforcing its malicious intent.
Although the site is currently offline, the observed infrastructure indicates a purposeful attempt to lure Kraken users into a crypto‑related gambling scam. Defenders should add the domain and its IP address to network‑level deny lists, monitor for related sub‑domains or URLs that may reuse the same hosting environment, and reinforce brand‑monitoring controls for Kraken to detect similar impersonation attempts. Continuous re‑scanning of the domain, especially if it reappears, is advised to capture any changes in detection rates or content.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
-
Status do domínio
Acessível → Inacessível
-
Status do domínio
Inacessível → Acessível
-
Status do domínio
Inacessível → Acessível
-
Status do domínio
Acessível → Inacessível
-
Status do domínio
Inacessível → Acessível
-
Status do domínio
Acessível → Inacessível
-
Status do domínio
Inacessível → Acessível
-
Status do domínio
Acessível → Inacessível
-
Status do domínio
Inacessível → Acessível
Mostrar tudo (1)
-
Status do domínio
Acessível → Inacessível
Tecnologias
9 tecnologias identificadas com alta confiança
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo