estederm[.]ru
“КРАКЕН — новости без фейков и рекламных вбросов”
Зведення доказів
Analysis indicates that the domain estederm.ru was registered on 21 February 2026 through RU‑CENTER‑RU and is currently taken offline. The site presented a page title in Russian, “КРАКЕН — новости без фейков и рекламных вбросов”, which directly references the target brand Kraken, confirming a brand‑impersonation intent. No SSL certificate is presented, meaning the site operated over plain HTTP, a common characteristic of low‑cost impersonation pages. DNS resolution points to IP address 186.2.175.37, which belongs to AS59692 (IQWeb FZ‑LLC) and is geolocated to Belarus. The hosting provider uses Cloudflare nameservers (celine.ns.cloudflare.com and earl.ns.cloudflare.com), suggesting the operator leveraged Cloudflare’s CDN for anonymity or traffic masking.
Reputation services flag the domain on three security blocklists, and it is explicitly listed by PhishDestroy, MetaMask, and SEAL as a malicious resource. The Gridinsoft trust score is 0 out of 100, indicating a complete lack of trust. VirusTotal analysis shows that 2 of 93 scanning engines flagged the domain, providing additional corroboration of malicious behavior. The limited detection count may reflect the domain’s brief exposure window before being taken offline. Uncertainties remain regarding the exact content served before takedown, the presence of any credential‑stealing forms, or the use of additional infrastructure such as command‑and‑control servers.
No SSL certificate, no public HTTP status code, and the absence of a detailed page snapshot prevent a full technical dissection of the payload. Defenders should block DNS resolution for estederm.ru at network perimeter and add the IP 186.2.175.37 to host‑based deny lists. Security teams should monitor for any future domains registered by the same registrar that resolve to the same ASN or use the same Cloudflare nameservers.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога