Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
kraken2trfqodidvlh4aa337cpzfrhdlfldhve5nf-onion[.]com
“KRAKEN”
kraken2trfqodidvlh4aa337cpzfrhdlfldhve5nf-onion.com — Bilinen son aktif (HTTP 301). Marka kimliğine bürünme: Kraken; Dolandırıcılık türü: Fake Exchange. Kanıt özeti: VirusTotal 6/91 (alphaMountain.ai, Chong Lua Dao, Fortinet, Gridinsoft, SOCRadar); URLQuery 3 alerts; Spamhaus DBL_PHISH; PhishDestroy score 83/100. Kayıt kuruluşu: NiceNIC.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain is a confirmed brand impersonation threat targeting Kraken, a major cryptocurrency exchange. The site mimics legitimate Kraken login or transaction pages to deceive users into entering credentials or transferring funds. Such impersonation domains are commonly used in crypto drainer attacks, where victims unknowingly authorize transactions that drain their wallets. The domain’s structure, including the use of an .onion address, suggests an attempt to evade detection and appear as an official darknet portal for Kraken services. Users who interact with this site risk financial loss, credential theft, and unauthorized access to their cryptocurrency holdings. Analysis indicates the domain was created on March 27, 2026, and is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. It resolves to the IP address 172.67.201.15, hosted on infrastructure associated with Cloudflare, Inc. in Canada. The domain is flagged by 8 out of 95 security vendors on VirusTotal, confirming its malicious nature. Additionally, it appears on one security blocklist and has been taken offline, though historical data remains a concern for retrospective threat analysis. The SSL certificate, issued by Let’s Encrypt (serial number E7), does not mitigate the risk, as malicious actors frequently use valid certificates to lend false legitimacy to phishing sites. Users who visited this domain should immediately revoke any active sessions or authorizations tied to Kraken or other cryptocurrency services. Change passwords for all crypto-related accounts, enable multi-factor authentication (MFA), and review transaction histories for unauthorized activity. If credentials or wallet details were entered, assume they are compromised and transfer remaining funds to a new, secure wallet. Monitor financial and account activity closely for signs of follow-up attacks, such as phishing emails or unauthorized login attempts. Organizations should update their blocklists to include this domain and its associated IP address to prevent future access. Given the elevated risk level, affected users are advised to report the incident to relevant cybersecurity authorities or their exchange’s fraud team for further investigation.
Ağ Güvenliği İstihbaratı Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | kraken2trfqodidvlh4aa337cpzfrhdlfldhve5nf-onion.com |
malicious | Sinkholed |
| OpenDNS | kraken2trfqodidvlh4aa337cpzfrhdlfldhve5nf-onion.com |
phishing | Phishing Block |
| Hagezi Threat Feed | kraken2trfqodidvlh4aa337cpzfrhdlfldhve5nf-onion.com |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-21 02:47:30 UTC
Teknolojiler · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of kraken2trfqodidvlh4aa337cpzfrhdlfldhve5nf-onion.com · checked Jun 26, 2026
Site Yapılandırma Analizi
Kanıtlar ve Dış Raporlar
PD-20260328-4EFCD4 Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin