kra47----------cc-c[.]ru
“krab1 - система авторизации с защитой данных”
kra47----------cc-c.ru — İçerik kullanılamıyor. Kanıt özeti: VirusTotal 12/95 (alphaMountain.ai, Bfore.Ai PreCrime, BitDefender, CRDF, CyRadar); PhishDestroy score 86/100. Kayıt kuruluşu: REGRU-RU.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
The domain kra47----------cc-c.ru was observed as part of a generic phishing operation and is currently taken offline. Registration data shows the domain was created on 06 December 2025 through the Russian registrar REGRU‑RU. DNS resolution points to the IPv4 address 91.236.116.20, which belongs to ASN 42237 operated by w1n ltd and is geolocated to Sweden. The authoritative name servers are ns1.armadns.com and ns2.armadns.com. No SSL certificate is presented, meaning the site was only reachable over HTTP, which is consistent with many low‑cost phishing deployments.
The page title returned by the server reads “krab1 – система авторизации с защитой данных”, indicating an attempt to masquerade as an authorization system, though the content has not been captured for further analysis. Multiple security controls have flagged the domain. PhishDestroy lists it as blocked, and a single security blocklist also contains the domain. The Gridinsoft trust scoring system assigns a rating of 0 out of 100, reflecting a complete lack of trust. VirusTotal reports that 12 of 95 antivirus and URL‑reputation engines flagged the domain as malicious, providing additional independent confirmation.
The site’s absence of HTTPS, combined with the low trust score and the detection count, suggests a high likelihood of phishing intent. Defenders should treat kra47----------cc-c.ru as a confirmed phishing indicator. Immediate actions include adding the domain and its resolving IP address to network and email filtering blocklists, updating intrusion‑prevention signatures, and monitoring for any re‑use of the underlying hosting infrastructure. Since the domain is already offline, continued surveillance of the associated IP range (91.236.116.0/24) and the hosting ASN may help detect future deployments that reuse the same provider. Organizations using URL‑filtering services should ensure the domain is present in their block lists to prevent accidental user exposure.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin