MALICIOUS — CRITICAL
kra22c[.]cc
This domain, kra22c.cc, is identified as a credential theft phishing infrastructure designed to harvest user login credentials through deceptive login portals.
- VirusTotal
- 6/94
- Blocklists
- No stored match
- Kullanılabilirlik
- Bilinen son aktif · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
kra22c.cc — Bilinen son aktif (HTTP 301). Dolandırıcılık türü: Credential Phishing. Kanıt özeti: VirusTotal 6/94 (ADMINUSLabs, alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet); Spamhaus DBL_PHISH; PhishDestroy score 83/100. Kayıt kuruluşu: Domains Etc.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
This domain, kra22c.cc, is identified as a credential theft phishing infrastructure designed to harvest user login credentials through deceptive login portals. Analysis indicates no direct association with a specific brand or cryptocurrency drainer kit, but the domain exhibits characteristics typical of credential harvesting campaigns, including the use of Let's Encrypt SSL certificates to lend an air of legitimacy. The lack of brand impersonation markers suggests a broad, opportunistic targeting strategy rather than a focused attack on a particular service or platform. Infrastructure analysis reveals the following technical indicators: the domain is flagged by 6 out of 95 security vendors on VirusTotal, indicating moderate detection but not universal recognition as malicious. It resolves to the IP address 86.54.24.57, a host that may be part of a larger bulletproof or compromised infrastructure. Registered through Domains Etc LLC on March 28, 2026, the domain's creation date is suspiciously recent, aligning with common phishing lifecycle patterns. AlienVault OTX records the domain in one threat intelligence pulse, while it appears on a single security blocklist, suggesting limited but growing awareness within the threat intelligence community. The SSL certificate, issued by Let's Encrypt (serial number E8), is valid and commonly used in both legitimate and malicious sites to evade browser warnings. As of the latest assessment, kra22c.cc has been taken offline, likely in response to detection or enforcement actions. However, the residual risk remains elevated due to the domain's recent registration and the potential for the infrastructure to resurface under a different name or IP. Users who may have interacted with this domain are advised to reset credentials for any accounts accessed during the exposure window, particularly if passwords were reused across services. Organizations should monitor for related indicators, including the resolving IP 86.54.24.57, and update blocklists to prevent future access attempts. The domain's registrar and hosting provider may have been notified, but proactive monitoring of newly registered domains with similar patterns is recommended to mitigate further credential theft risks.
Veri kapsamı12 recorded checks
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
VirusTotal Analizi
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.