kra46at[.]ideltower[.]ru
“kra46 - AT архитектурный концепт высотных зданий”
kra46at.ideltower.ru — Контент недоступен. Сводка доказательств: VirusTotal 10/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Fortinet); PhishDestroy score 80/100. Регистратор: REGRU-RU.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of the domain kra46at.ideltower.ru shows that it was registered on December 11, 2024 and subsequently resolved to the IPv4 address 193.105.134.30, which is hosted within Autonomous System AS42237 operated by w1n ltd in the Southeast region. The domain is delegated to the name servers ns1.armadns.icu and ns2.armadns.icu, and no TLS certificate was observed during the scan, indicating that the site was served over plain HTTP only. The page title returned by the server was "kra46 - AT архитектурный концепт высотных зданий," suggesting the site attempts to present itself as an architectural concept service for high‑rise buildings, possibly targeting Russian‑speaking users.
The domain is currently taken offline, but historical data indicates that it was flagged by multiple security controls: PhishDestroy listed the domain as blocked, VirusTotal recorded detections by 10 of 95 AV engines, and at least one public blocklist contained the address. The Gridinsoft trust score of 0/100 further reinforces its malicious classification. Registrar information points to REGRU‑RU, a Russian registrar, which aligns with the Cyrillic page title.
While the exact phishing kit or credential‑harvesting page has not been captured, the combination of a newly created domain, lack of SSL, low trust metrics, and multiple vendor detections supports an elevated risk rating. Defenders should add the IP 193.105.134.30 and the domain to network‑level blocklists, monitor DNS queries for this host, and ensure that any inbound traffic to the associated name servers is dropped. Continuous re‑evaluation is advised in case the actor re‑hosts the payload on a different address, as the infrastructure components (registrar and hosting ASN) remain active.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание