MALICIOUS — HIGH
kra0[.]org
4 of 93 security engines flagged the domain; the latest stored check returned HTTP 502.
- VirusTotal
- 4/93
- Blocklists
- No stored match
- Доступність
- Контент недоступний · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
kra0.org — Контент недоступний (HTTP 502). Зведення доказів: VirusTotal 4/93 (SOCRadar); PhishDestroy score 65/100. Реєстратор: Gname.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Digest
kra0.org is classified high with an evidence score of 65/100. 4 of 93 security engines flagged the domain. Registered 16 Nov 2025 via Gname.com Pte. Ltd., hosted on 172.67.201.59 (CLOUDFLARENET, US, US). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture.
Stored generated summary (templated)cerebras · 24.07.2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
The domain kra0.org was registered on 2025-11-16 via Gname.com Pte. Ltd. It resolves to 172.67.201.59, an address owned by Cloudflare (AS13335) located in the United States. No TLS certificate is presented, indicating HTTP‑only service. The only visible page title is “Captcha”, and no further content has been captured. Gridinsoft assigns a trust score of 0/100, effectively marking the domain as malicious.
VirusTotal reports that 4 of 93 scanned security vendors flagged the domain, reinforcing the suspicion. The domain is listed on a single external blocklist and has been actively blocked by the PhishDestroy filtering service. Nameserver records point to ariadne.ns.cloudflare.com and viddy.ns.cloudflare.com, confirming Cloudflare DNS usage. The site is currently taken offline, which limits real‑time observation but does not remove the historical indicators of abuse.
Evidence is limited to registration metadata, hosting information, the low trust score, and the modest vendor detections; no malware payloads, phishing page screenshots, or credential‑harvesting URLs have been disclosed. Defenders should continue to block kra0.org at perimeter filters, update URL reputation feeds, and monitor for re‑use of the underlying IP address or Cloudflare nameservers in future campaigns. Additional investigation should focus on any residual HTTP requests that may still target the domain and on correlating the four vendor detections to identify the specific malicious behaviors observed.
Обсяг даних12 recorded checks
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.