kraktag[.]ink
“Krak | Global Money App | Spend, Send & Grow | Krak”
Kanıt özeti
Analysis of the domain kraktag.ink indicates a high‑risk brand‑impersonation campaign targeting the Krak financial application. The domain was registered on May 09, 2026 through Cloudflare, Inc., and resolves to the Cloudflare‑hosted IP address 104.21.67.196, which is geolocated to Canada. The site presents a page title identical to the legitimate Krak app, "Krak | Global Money App | Spend, Send & Grow | Krak," suggesting intentional brand mimicry to deceive users.
Infrastructure inspection shows the domain is served behind Cloudflare’s network, using Google Trust Services / WE1 for its SSL certificate, and the authoritative nameservers are uma.ns.cloudflare.com and thaddeus.ns.cloudflare.com. The site returns an HTTP 301 redirect, a behavior commonly leveraged in credential‑harvesting pages to forward victims to malicious payloads. Reputation metrics are poor: Gridinsoft assigns a trust score of 0 out of 100, the domain appears on one security blocklist, and PhishDestroy has already blocked it.
Threat intelligence corroborates the malicious nature of the domain. It appears in a single AlienVault OTX pulse, and VirusTotal reports that one of ninety‑five scanned security vendors flagged the domain as malicious. These independent detections reinforce the likelihood that kraktag.ink is being used to harvest credentials or financial information under the guise of the Krak brand.
While the observable indicators confirm active abuse, the precise phishing kit, command‑and‑control infrastructure, or victim count remain undisclosed. Defenders should prioritize blocking the domain at network perimeter devices and updating URL filtering policies to include kraktag.ink. Continuous monitoring of related Cloudflare‑hosted IP ranges and rapid sharing of any new indicators with threat‑sharing communities are recommended to curb further propagation of this impersonation campaign.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin