kraken3yvbvzmhytnrnuhsy772i6dfobofu652e27f5hx6y5cpj7rgyd-onion[.]org
kraken3yvbvzmhytnrnuhsy772i6dfobofu652e27f5hx6y5cpj7rgyd-onion.org — Непроверенный. Олицетворение бренда: Kraken; Тип мошенничества: Fake Exchange. Сводка доказательств: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); PhishDestroy score 76/100. Регистратор: Gname 398.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain kraken3yvbvzmhytnrnuhsy772i6dfobofu652e27f5hx6y5cpj7rgyd-onion.org is a fake exchange site that mimics Kraken, a well-known cryptocurrency exchange. It is currently taken down, but at its peak, it was flagged by 1 out of 94 vendors on VirusTotal, indicating limited detection. The domain was registered through Gname 398 Inc and hosted on an IP managed by CloudFlare, Inc., located in Canada.
This phishing domain aimed to deceive users into believing they were accessing the legitimate Kraken platform. By leveraging the trusted Let's Encrypt SSL certificate, the site likely appeared secure to unsuspecting visitors. The use of a complex and seemingly random domain name is a common tactic to evade detection and confuse users.
Despite its takedown, the domain highlights the ongoing threat of fake exchange sites within the cryptocurrency sector. PhishDestroy's inclusion of this domain in public blocklists underscores the importance of early detection in mitigating phishing threats. The limited VirusTotal detection count reflects the freshness of the threat, as phishing domains often exploit the gap between registration and antivirus database updates.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Анализ конфигурации сайта
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание