kraken[.]krab2------cc[.]ru
“Кракен krab2 - платформа CC кэшбэка для онлайн-покупок”
kraken.krab2------cc.ru — Контент недоступен. Олицетворение бренда: Kraken; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 9/93 (ChainPatrol, BitDefender, CRDF, CyRadar, Fortinet); PhishDestroy score 77/100. Регистратор: REGRU-RU.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of the domain kraken.krab2------cc.ru shows multiple indicators of malicious activity aligned with a brand‑impersonation campaign targeting the cryptocurrency exchange Kraken. The site was registered on 20 December 2025 through the Russian registrar REGRU‑RU, and its creation date places it well within the operational window of recent crypto‑related frauds. The page title captured in the intelligence, “Кракен krab2 - платформа CC кэшбэка для онлайн‑покупок”, references a cashback platform and includes the brand name “Кракен”, suggesting an attempt to lure users by mimicking legitimate Kraken services. The domain resolves to IP 91.236.116.210, which is assigned to AS42237 (w1n ltd) in Sweden, and the hosting provider is listed under the armadns.com nameservers.
No TLS certificate is present, meaning the site would have been served over plain HTTP, a common characteristic of low‑effort phishing or scam pages. Reputation checks reinforce the suspicion: Gridinsoft assigns a trust score of 0 / 100, the domain appears on one security blocklist, and PhishDestroy has actively blocked it. VirusTotal reports that 9 of 93 scanning engines flagged the domain, indicating a modest but notable detection rate. The threat classification in the intelligence labels the operation as a “Crypto Scam”, and the domain is explicitly noted to impersonate Kraken, confirming a targeted brand‑spoofing motive.
The current offline status limits immediate interaction, but the infrastructure—registration details, hosting, lack of encryption, and low trust rating—remains usable for future campaigns. Defensive recommendations include adding the domain and its resolving IP to outbound and inbound blocklists, monitoring any related sub‑domains under the same nameservers, and applying URL filtering rules for content that references Kraken or cryptocurrency cashback schemes. Continuous re‑scanning with multi‑engine services is advised to capture any updates to detection status.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание