krkn32[.]top
“Kraken Darknet Market | Оригинальное зеркало | Единственный официальный вход”
Сводка доказательств
Analysis of krkn32.top, observed as a brand‑impersonation site targeting the Kraken cryptocurrency exchange, was performed on 24 July 2026. The domain was registered on 21 February 2026 and resolves to the IP address 172.67.151.230, which belongs to Cloudflare, Inc. (AS13335) and is geolocated to the United States. The site’s SSL certificate is identified only as “WE1”, providing no additional validation of ownership. The page title returned from the server reads “Kraken Darknet Market | Оригинальное зеркало | Единственный официальный вход”, explicitly referencing a darknet market and using Russian language to suggest an “original mirror” and “the only official entry”. This title aligns with the declared scam type of a crypto‑related fraud.
Infrastructure analysis indicates that the domain is currently offline, and the phishing‑specific blocklist PhishDestroy has already taken the domain down. Independent security platforms have listed the domain on a single blocklist, and the Gridinsoft trust score is 0 out of 100, reflecting an extremely low reputation. VirusTotal scans show that three of ninety‑five antivirus engines flagged the domain, confirming the presence of malicious activity despite the limited detection count. The evidence points to a deliberate attempt to impersonate the Kraken brand and lure victims into a fake darknet marketplace, likely to harvest cryptocurrency credentials or funds.
However, the exact payload, credential‑stealing mechanisms, and any associated command‑and‑control infrastructure have not been disclosed in the available data, leaving the full attack chain uncertain. Defenders should add krkn32.top to their deny‑list for web‑filtering solutions, enforce TLS inspection to capture any hidden traffic, and monitor for connections to the Cloudflare IP 172.67.151.230 that may originate from internal hosts.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
10 внешних источников под наблюдением Совпадений нет
Криминалистическая аналитика
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание