kraoi[.]com
kraoi.com için kimlik avı ve güvenlik kontrolü
“Welcome to AI Stock”
kraoi.com — İçerik kullanılamıyor (HTTP 502). Dolandırıcılık türü: Generic Phishing. Kanıt özeti: VirusTotal 2/94 (ChainPatrol, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Kayıt kuruluşu: Gname.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Analysis of kraoi.com shows a newly registered domain (creation date March 12, 2026) that resolves to the Cloudflare‑owned address 188.114.96.3, ASN 13335, located in the United States. The site was protected by Cloudflare SSL, presenting a Managed CA certificate (SHA‑1 fingerprint 1f7bed55a379bd5f2f53b866b0cbbf89) and enforcing HSTS. HTTP/3 was observed, along with client‑side frameworks Vue.js and Swiper, and Cloudflare Browser Insights telemetry. The page title returned by the server is "Welcome to AI Stock," indicating an attempt to lure victims with a financial‑themed lure, though no specific brand beyond the generic term "AI Stock" is identified.
The domain’s MX record points to mail.emb666.com (priority 1), and the registrar is listed as Gname.com Pte. Ltd. Nameserver delegation uses sharon.ns.cloudflare.com and sterling.ns.cloudflare.com, both Cloudflare‑managed. VirusTotal scans recorded two detections out of ninety‑four security vendors, and the domain appears on three public blocklists, with explicit blocks from PhishDestroy, MetaMask, and SEAL. Gridinsoft assigned a trust score of zero out of one hundred, reinforcing the malicious assessment. The site is currently taken offline, but its infrastructure—particularly the shared Cloudflare IP and the use of generic front‑end libraries—suggests it could be re‑hosted quickly.
Defenders should add kraoi.com, its resolved IP 188.114.96.3, and associated MX host mail.emb666.com to outbound and inbound block lists, monitor DNS queries for re‑registration of the same name or similar aliases, and incorporate the observed SSL fingerprint and technology stack into detection rules. Continuous threat‑intel feeds should be consulted for any resurgence, and any emails originating from the listed MX host should be scrutinized for phishing content. The limited detection count indicates early exposure; proactive containment now can prevent future credential‑harvesting campaigns.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Adli İstihbarat
Teknolojiler · 6 identified
Progressive JavaScript framework for building user interfaces.
Modern mobile touch slider with hardware-accelerated transitions.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of kraoi.com · checked Mar 12, 2026
Kanıtlar ve Dış Raporlar
PD-20260312-4E65CB Recipient: complaint@gname.com Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin