krab1-cc[.]kartina-m[.]ru
“krab1-cc.kartina-m.ru”
krab1-cc.kartina-m.ru — Контент недоступен. Сводка доказательств: VirusTotal 10/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Fortinet); Google Safe Browsing flagged; PhishDestroy score 80/100. Регистратор: REGRU-RU.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of krab1-cc.kartina-m.ru indicates that the domain was registered on March 06, 2025 through the REGRU‑RU registrar and is hosted on a server located in Sweden, ASN AS42237 operated by w1n ltd, reachable at 193.105.134.30. The authoritative name servers are ns1.regerey.com and ns2.regerey.com. No TLS certificate is presented, meaning the site is served only over HTTP. The page title returned by the server is identical to the domain name, providing no additional context.
Reputation services have flagged the domain: ten of ninety‑five VirusTotal scanners reported it as malicious, Google Safe Browsing classifies it as a social‑engineering threat, and it appears on a single security blocklist. PhishDestroy has taken the domain offline, and the current status is reported as offline. Gridinsoft assigns a trust score of zero out of one hundred, reinforcing the malicious assessment. The domain is listed as a generic phishing campaign, but the specific target brand or credential‑stealing page has not been disclosed in the available intelligence.
Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any residual traffic to 193.105.134.30, and consider adding the IP address to host‑based deny lists. Because the site lacks SSL, any attempted connections would be unencrypted, allowing potential interception, but the primary risk remains credential harvesting. Continuous observation of the registrar REGRU‑RU and the hosting ASN is advised to detect possible re‑use of the infrastructure for future campaigns.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание