kraken[.]krab2---cc[.]ru
“Кракен krab2 - безопасная AT авторизация для покупателей”
kraken.krab2---cc.ru — Контент недоступен. Олицетворение бренда: Kraken; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 13/93 (ChainPatrol, BitDefender, Certego, CRDF, CyRadar); PhishDestroy score 89/100. Регистратор: REGRU-RU.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain kraken.krab2---cc.ru was registered on December 20, 2025 through the REGRU-RU registrar and resolves to the IPv4 address 91.236.116.210, an AS42237 host located in Sweden and operated by w1n ltd. The authoritative name servers for the zone are ns1.armadns.com and ns2.armadns.com. No TLS certificate was presented for the site, indicating that connections were unsecured. A scan on VirusTotal recorded 13 detections out of 93 security engines, and the domain appears on a single external blocklist.
Gridinsoft assigned a trust score of 0 out of 100, and the site was actively blocked by the PhishDestroy service. The page title retrieved during analysis reads "Кракен krab2 - безопасная AT авторизация для покупателей," which references the Kraken brand and describes a “secure AT authorization for buyers.” The campaign is classified as a crypto‑related scam that impersonates Kraken, consistent with the brand‑impersonation threat type and the elevated risk rating. As of the report date, July 23, 2026, the site is offline, preventing immediate interaction, but the infrastructure details remain valid for threat‑intel correlation.
Defensive teams should update network and endpoint filters to block connections to 91.236.116.210 and any subdomains of kraken.krab2---cc.ru, enforce DNS‑based allow‑list policies that exclude the known name servers, and monitor for future activity using the registrar and ASN indicators. Because the visual content of the landing page has not been captured, analysts should treat any unverified claims about page layout or credential capture mechanisms as uncertain until a live sample is observed. Continuous monitoring of VirusTotal, phishing‑filter feeds, and public reputation services is advised to detect any re‑hosting attempts that reuse the same domain name or hosting infrastructure.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание