kra46at[.]itsonroads[.]ru
“kra46 - AT-платформа для автопутешествий”
kra46at.itsonroads.ru — İçerik kullanılamıyor. Kanıt özeti: VirusTotal 12/95 (BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker, Fortinet); PhishDestroy score 86/100. Kayıt kuruluşu: REGRU-RU.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
The domain kra46at.itsonroads.ru was registered on December 01, 2024 through the REGRU-RU registrar and is currently listed as offline. Its authoritative nameservers are ns1.regerey.com and ns2.regerey.com, and DNS resolution points to the IPv4 address 193.105.134.30, which belongs to AS42237 w1n ltd and is geolocated in Sweden. No TLS certificate was observed for the host, indicating that connections are served over plain HTTP. The public-facing page carries the title "kra46 - AT-платформа для автопутешествий", suggesting a Russian-language travel‑related service, but the content has not been examined for additional indicators.
Gridinsoft, a local trust scoring service, assigned a score of 0 out of 100, reflecting a lack of reputation. The domain appears on a single security blocklist and has been actively blocked by the PhishDestroy feed, reinforcing its classification as malicious. VirusTotal scans reported 12 detections out of 95 participating security engines, confirming that multiple independent scanners flag the domain as suspicious.
The risk level is elevated, and while the site is presently offline, the infrastructure—namely the hosting IP and DNS configuration—remains observable and could be reactivated. Defenders should continue to monitor the associated IP address and nameservers for future resolution attempts, ensure that web proxies and email gateways block any URLs containing the domain, and incorporate the domain into threat‑intel feeds used for automated blocking. Because the page title is the only visible artifact, further analysis of any archived HTTP responses would be needed to determine the exact phishing payload or credential‑capture mechanisms employed.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin