kraken[.]krab2------cc[.]ru
“Кракен krab2 - платформа CC кэшбэка для онлайн-покупок”
kraken.krab2------cc.ru — İçerik kullanılamıyor. Marka kimliğine bürünme: Kraken; Dolandırıcılık türü: Crypto Scam. Kanıt özeti: VirusTotal 9/93 (ChainPatrol, BitDefender, CRDF, CyRadar, Fortinet); PhishDestroy score 77/100. Kayıt kuruluşu: REGRU-RU.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Analysis of the domain kraken.krab2------cc.ru shows multiple indicators of malicious activity aligned with a brand‑impersonation campaign targeting the cryptocurrency exchange Kraken. The site was registered on 20 December 2025 through the Russian registrar REGRU‑RU, and its creation date places it well within the operational window of recent crypto‑related frauds. The page title captured in the intelligence, “Кракен krab2 - платформа CC кэшбэка для онлайн‑покупок”, references a cashback platform and includes the brand name “Кракен”, suggesting an attempt to lure users by mimicking legitimate Kraken services. The domain resolves to IP 91.236.116.210, which is assigned to AS42237 (w1n ltd) in Sweden, and the hosting provider is listed under the armadns.com nameservers.
No TLS certificate is present, meaning the site would have been served over plain HTTP, a common characteristic of low‑effort phishing or scam pages. Reputation checks reinforce the suspicion: Gridinsoft assigns a trust score of 0 / 100, the domain appears on one security blocklist, and PhishDestroy has actively blocked it. VirusTotal reports that 9 of 93 scanning engines flagged the domain, indicating a modest but notable detection rate. The threat classification in the intelligence labels the operation as a “Crypto Scam”, and the domain is explicitly noted to impersonate Kraken, confirming a targeted brand‑spoofing motive.
The current offline status limits immediate interaction, but the infrastructure—registration details, hosting, lack of encryption, and low trust rating—remains usable for future campaigns. Defensive recommendations include adding the domain and its resolving IP to outbound and inbound blocklists, monitoring any related sub‑domains under the same nameservers, and applying URL filtering rules for content that references Kraken or cryptocurrency cashback schemes. Continuous re‑scanning with multi‑engine services is advised to capture any updates to detection status.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin