kra9[.]me
“KRAKEN”
Сводка доказательств
Analysis of the domain kra9.me, observed on July 24 2026, indicates a brand‑impersonation campaign targeting the cryptocurrency exchange Kraken. The domain was registered on 5 November 2025 through Virtualia LLC and is hosted on Cloudflare’s network (AS13335) with the IP address 104.21.85.29 located in the United States. DNS resolution points to the Cloudflare authoritative name servers aryanna.ns.cloudflare.com and lloyd.ns.cloudflare.com. No TLS certificate is presented, and the site does not serve HTTPS content. The HTTP response, when captured before the takedown, returned a page whose title is exactly “KRAKEN”, matching the targeted brand.
The site is classified as a crypto‑scam in the intelligence feed and is listed on a single security blocklist. PhishDestroy has taken the domain offline, and the current status is reported as offline. Reputation scoring from Gridinsoft assigns a trust score of 0 out of 100, indicating a malicious classification. VirusTotal analysis shows that 1 of 93 scanned vendors flagged the domain, confirming at least one detection. The limited detection count suggests that many scanners have not yet identified the payload, but the presence of a flagging engine underscores the malicious intent.
Uncertainty remains regarding the specific payload or phishing page content because the site is no longer reachable and no additional sandbox or URL‑capture data are available. Defenders should block the IP address 104.21.85.29 and the domain name kra9.me at the DNS level, add the domain to internal blocklists, and monitor for any future registrations that reuse the same registrar or name‑server pattern. Continuous telemetry from Cloudflare‑originated traffic and correlation with Kraken‑related credential‑theft alerts will help detect any residual activity. The evidence compiled here supports an elevated risk rating and justifies proactive containment.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
Криминалистическая аналитика
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание