Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@iqweb.io.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
krab--5----cc[.]ru
“Krab5 CC | Онлайн агрегатор по созданию сайтов!”
krab--5----cc.ru — Непроверенный. Олицетворение бренда: Kraken; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 2/93 (Gridinsoft, SOCRadar); PhishDestroy score 56/100. Регистратор: RU-CENTER-RU.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of krab--5----cc.ru shows a confirmed brand‑impersonation campaign targeting the cryptocurrency exchange Kraken. The domain was registered on 21 February 2026 through RU‑CENTER‑RU and resolves to IP 186.2.175.37, which is announced by AS59692 (IQWeb FZ‑LLC) and geolocated to Belarus. The host returns HTTP 502, indicating the web service is currently unavailable, and the site is marked as offline. A Let’s Encrypt R12 certificate covers the domain, confirming TLS is in use despite the service disruption. Cloudflare nameservers (marjory.ns.cloudflare.com and terry.ns.cloudflare.com) are configured, suggesting the operators leveraged Cloudflare’s CDN and DNS protection.
The page title discovered during a prior fetch reads “Krab5 CC | Онлайн агрегатор по созданию сайтов!”, a generic Russian‑language phrase that does not reference Kraken, but the documented scam type explicitly lists brand impersonation of Kraken. Technical footprints include Yandex.Metrika analytics and DDoS‑Guard protection, both common in malicious Russian‑hosted sites. VirusTotal scans flagged the domain by 2 of 93 vendors, and Gridinsoft assigns a trust score of 0 / 100. Independent blocklists and security services (PhishDestroy, MetaMask, SEAL) have already listed the domain, and it appears on three additional blocklists.
The combination of low trust scoring, vendor detections, and active blocklisting indicates a high probability of malicious intent. Uncertainty remains around the exact payload or credential‑harvesting mechanisms because the site is offline and no page content has been captured. Defenders should continue to block the domain at perimeter and DNS layers, monitor the hosting IP for related activity, and update incident response playbooks to include Kraken‑related impersonation vectors. Threat intelligence feeds should be refreshed with the domain’s identifiers to ensure rapid detection of any re‑use of the same infrastructure.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 2 identified
Yandex.Metrica is a free web analytics service that tracks and reports website traffic.
metrika.yandex.com 100% уверенностиDDoS-Guard is a Russian Internet infrastructure company which provides DDoS protection, content delivery network services, and web hosting services.
ddos-guard.net 100% уверенностиАнализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of krab--5----cc.ru · checked Mar 6, 2026
Доказательства и внешние отчеты
PD-20260202-91B0BD Recipient: abuse@iqweb.io Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание