kra-43-cc-c[.]ru
“Kra43 CC — лаборатория запахов и авторской ароматерапии”
kra-43-cc-c.ru — Неперевірений. Зведення доказів: VirusTotal 15/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); Google Safe Browsing flagged; Spamhaus DBL_SPAM; PhishDestroy score 98/100. Реєстратор: UK-WIN (ASN: 42237).
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain kra-43-cc-c.ru was observed in a generic phishing campaign targeting Russian‑language users. The site resolved to the IPv4 address 193.105.134.74, which is geolocated to Sweden and is announced by AS42237 belonging to w1n ltd. Registration details show the domain was created through the UK‑WIN registrar, which is associated with the same ASN. The authoritative name servers are sureena.ns.cloudflare.com and woz.ns.cloudflare.com, indicating the use of Cloudflare’s DNS infrastructure. No TLS certificate was presented, leaving the HTTP service unencrypted.
The page title returned by the server was “Kra43 CC — лаборатория запахов и авторской ароматерапии”, suggesting a focus on a laboratory of scents and aromatherapy, but the content has not been examined because the service is currently offline. Reputation checks provide multiple indicators of compromise. Gridinsoft assigned a trust score of 0 out of 100, the lowest possible rating. Google Safe Browsing classified the domain as a social‑engineering threat. VirusTotal recorded 14 detections out of 95 scanned scanners, reflecting a moderate level of consensus among security vendors.
The domain is listed on a single public blocklist and has been actively blocked by the PhishDestroy mitigation service. The available evidence points to a deliberately crafted phishing infrastructure that leverages reputable DNS services while avoiding encryption to simplify credential capture. However, the offline status prevents direct verification of the payload or credential‑collection mechanisms. Defenders should continue to block the domain at network perimeter devices, update DNS filtering rules to include the observed nameservers, and monitor the associated IP address for any resurgence of activity. Additional analysis of historic HTTP traffic, if available, could clarify the exact phishing methodology and target profile.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога