kra46-cc[.]farmaciaitali24[.]ru
“kra46 - круглосуточный CC-помощник в мире итальянской медицины”
kra46-cc.farmaciaitali24.ru — Контент недоступен. Тип мошенничества: Investment Scam. Сводка доказательств: VirusTotal 13/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; PhishDestroy score 89/100. Регистратор: REGRU-RU.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of kra46-cc.farmaciaitali24.ru shows a high‑risk investment phishing operation that has been taken offline as of the report date, July 23 2026. The domain was registered on December 11 2024 through the Russian registrar REGRU-RU and resolves to the IPv4 address 193.105.134.30, which is advertised as belonging to AS42237 w1n ltd in Sweden. No SSL certificate is present, indicating that the site served only HTTP content. The page title retrieved during earlier crawls reads "kra46 - круглосуточный CC‑помощник в мире итальянской медицины," suggesting a Russian‑language front that references the Italian medical sector, but the content has not been publicly released for further forensic review.
Reputation data shows the domain appears on a single security blocklist, PhishDestroy, and Google Safe Browsing flags it for social engineering. VirusTotal scans returned 13 detections out of 95 vendors, reinforcing the malicious classification. Gridinsoft assigned a trust score of zero out of one hundred, and the nameservers ns1.armadns.icu and ns2.armaddns.icu are associated with generic dynamic DNS services, a pattern often leveraged by threat actors to rapidly redeploy infrastructure. Given the offline status, immediate mitigation focuses on preventing re‑use of the hosting IP and the identified nameservers.
Defenders should add 193.105.134.30 to network blocklists, monitor for new domains registered with REGRU-RU that resolve to the same IP range, and enforce URL filtering for the domain and its parent zone. Continuous observation of PhishDestroy and Google Safe Browsing updates is advised to capture any re‑emergence of the site. The combination of multiple vendor detections, a zero trust score, and a targeted investment scam narrative warrants a high‑severity incident response and extended monitoring of related infrastructure.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание