darknet-kraken[.]net
“Kraken Onion | Кракен Маркетплейс Официальный Сайт”
darknet-kraken.net — Неперевірений. Уособлення бренду: Kraken; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 14/95 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); Spamhaus DBL_PHISH; PhishDestroy score 92/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain darknet-kraken.net was observed as a brand‑impersonation site targeting the cryptocurrency exchange Kraken. The site is currently offline, having been taken down after detection. Registration data show the domain was created on 14 November 2025 and was registered through NiceNIC International Group Co., Limited. Authoritative nameservers ns1-ams.v-sys.org and ns2-ams.v-sys.org resolve the domain to the IPv4 address 195.26.87.170, which belongs to AS43641 SOLLUTIUM EU Sp z.o.o. and is geolocated in the Netherlands.
No TLS certificate was presented during the brief observation period, indicating the site operated without HTTPS protection. The page title returned by the server was “Kraken Onion | Кракен Маркетплейс Официальный Сайт”, confirming the intent to masquerade as an official Kraken marketplace. VirusTotal scans recorded 14 detections out of 95 security vendors, and the domain was listed on a single security blocklist. PhishDestroy also flagged the domain as malicious. Evidence from other sources such as Safe Browsing, OTX, or additional blocklists was not available.
The precise content of the site, including any credential‑collection forms or payment instructions, cannot be confirmed because the site is no longer reachable. Defenders should continue to block the IP address 195.26.87.170 and add darknet-kraken.net to local deny lists. Monitoring for re‑registration or the appearance of similarly named domains using the same registrar or nameserver pattern is recommended, as the infrastructure suggests a reusable hosting setup. Incorporating the detection count and blocklist information into automated threat‑intel feeds will improve early warning for organizations that rely on Kraken services.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-16 02:57:51 UTC
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога