Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
kra23-at[.]cc
Kanıt özeti
The domain kra23-at.cc was registered on 21 February 2026 through Gname.com Pte. Ltd. and is currently listed as taken offline. DNS resolution points to the Cloudflare‑owned address 188.114.97.3, which resides in the United States under ASN 13335 (Cloudflare, Inc.). The authoritative nameservers are matias.ns.cloudflare.com and nucum.ns.cloudflare.com, indicating the use of Cloudflare’s DNS and edge services. HTTPS is presented with a Google Trust Services / WE1 certificate, confirming a valid TLS chain issued by a reputable CA, but the certificate alone does not attest to the legitimacy of the hosted content.
A request to the site returns HTTP 403 and the page title “Just a moment…”, which is typical of Cloudflare challenge pages rather than a visible phishing landing page. The site’s Gridinsoft trust score is 0 / 100, reflecting a poor reputation. It appears on one public security blocklist and has been specifically blocked by the PhishDestroy service, suggesting that threat‑intelligence feeds have identified it as malicious. VirusTotal reports that eight of ninety‑three scanners flagged the domain, providing additional independent confirmation of suspicious activity.
The available evidence points to a generic phishing operation that has already been taken offline, but the underlying infrastructure—Cloudflare edge, a publicly trusted TLS certificate, and a low‑reputation trust score—remains reusable for future campaigns. Because the content has not been publicly captured, the exact phishing vector and targeted brand cannot be confirmed at this time. Defenders should continue to block the domain at the network perimeter, add the associated IP address 188.114.97.3 to deny lists, and monitor for any re‑registration or reuse of the same nameservers. Regularly updating URL filtering and threat‑intel feeds will help capture any resurrection of the domain or its infrastructure in new malicious campaigns.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260214-9769A0- Yakalanan sayfa başlığı
- Captcha
- PDF belgesi
- PDF kanıtı
Hukuki dayanak
Kanıtın tam metni
Acceptable Use Policy (AUP): The domain kra23-at.cc is engaged in phishing activities, which directly contravenes the AUP prohibiting illegal activities and fraud.
Terms of Service (TOS): The registrar reserves the right to suspend or terminate services for violations, and the operation of this domain constitutes a clear violation of these terms due to its involvement in deceptive practices.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, which includes phishing schemes designed to obtain sensitive information unlawfully.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities using electronic communications, which is applicable to the activities conducted by kra23-at.cc.
Anti-Phishing Consumer Protection Act: This act aims to combat phishing and related fraudulent activities, making it illegal to engage in deceptive practices intended to obtain personal information.
Regulatory Note: Failure to take immediate action against this domain may expose your organization to legal liability and regulatory scrutiny. It is imperative to comply with your AUP and TOS to mitigate potential risks.
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | kra23-at.cc |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of kra23-at.cc · checked Mar 6, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin