kra-40--at[.]cc
“KRA - всегда свежие продукты в нашем маркете”
kra-40--at.cc — Неперевірений. Зведення доказів: VirusTotal 12/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Spamhaus DBL_PHISH; PhishDestroy score 86/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of the domain kra-40--at.cc indicates it is a fraudulent phishing site targeting Russian-speaking users under the guise of a grocery marketplace. The domain was registered on February 21, 2026, through NiceNIC International Group Co., Limited, and is currently offline as of July 23, 2026. Infrastructure analysis reveals the domain resolved to the IP address 193.124.112.251, hosted on AS48347 (JSC Mediasoft ekspert) in Russia. The page title, 'KRA - всегда свежие продукты в нашем маркете,' suggests an attempt to impersonate a legitimate grocery or retail service, though no specific brand is confirmed in the available data.
Security vendors have flagged this domain, with 15 out of 95 engines on VirusTotal detecting malicious activity. The domain appears on at least one security blocklist and is blocked by PhishDestroy, further supporting its classification as a phishing threat. No SSL certificate was present, which is atypical for legitimate e-commerce sites and increases the likelihood of credential interception. The use of DNSPod nameservers (a.dnspod.com, b.dnspod.com, c.dnspod.com) is consistent with domains used in phishing campaigns, though not inherently malicious on its own.
While the domain is currently offline, defenders should treat it as a confirmed phishing threat. Organizations are advised to block the domain and its associated IP (193.124.112.251) at the network level, update endpoint protection signatures, and monitor for any re-emergence or related infrastructure. The lack of SSL and the domain's recent creation, combined with detection by multiple security vendors, provide sufficient evidence to classify this as an elevated-risk phishing operation. No additional details about the phishing kit or exact victim targeting are available at this time.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Latest Classified Outcome 2026-08-14 03:11:24 UTC
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260212-2CF25F Recipient: abuse@nicenic.net Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога