Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
kra39at[.]com
“Kra39.at – Рабочее зеркало kra39”
Збережене спостереження
Зафіксована відмінність заголовків
PhishDestroy identifies kra39at.com as an active crypto-draining phishing domain designed to trick visitors into approving malicious wallet transactions that silently transfer their cryptocurrency to attacker-controlled addresses. When loaded, the page mimics a legitimate crypto service login or token swap interface, prompting users to connect their wallets or sign transactions that drain funds instead of executing the promised swap or withdrawal. This type of attack is called a crypto drainer and is one of the fastest-growing threats in Web3, often embedded on malicious ads, fake airdrop sites, or hijacked social-media accounts. This domain was flagged by PhishDestroy as a crypto drainer on November 03, 2024, the same day it was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. Security vendor scans via VirusTotal indicate that 2 out of 95 engines detect malicious activity associated with kra39at.com. The site resolves to IP address 188.114.97.3 and holds an SSL certificate issued by Google Trust Services, which attackers often use to appear legitimate. Due to the low detection rate, the domain currently carries an elevated risk level, meaning it can evade some automated filters and reach real users. If you visited kra39at.com, disconnect your wallet immediately and revoke any permissions you may have granted. Never sign wallet transactions from unknown sites, and enable transaction simulation tools or hardware wallet confirmations to block unauthorized transfers. Clear your browser cache and cookies, and consider running a malware scan on your device. Report the domain to your wallet provider and to PhishDestroy to help protect others. Share this warning on social platforms or crypto forums to raise awareness and prevent further victims.
Запис надісланого повідомлення
Знімок надісланих доказів
- Надіслано
- Записи журналу
- 1
- ID справи
PD-20260327-17D09B- Заголовок збереженої сторінки
- Kra39.at – Рабочее зеркало kra39
- PDF-файл
- PDF із доказами
Правова підстава
Повний текст доказів
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Розвіддані з мережевої безпеки Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | kra39at.com |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Перевірка за блок-листами
Джерел: 10 · синхронізовано 10.08.2026
Хронологія виявлення
Збережені спостереження у хронологічному порядку.
-
Доступність
Доступність: уперше зафіксовано як unknown
993d00c35140 -
Доступність
Доступність: unknown → live_content
f5732ac012ee -
Доступність
Доступність: live_content → redirected
f45e1297c3c6 -
Доступність
Доступність: redirected → unknown
145f0224b9f5 -
Доступність
Доступність: unknown → redirected
12a141bf6c19 -
Доступність
Доступність: redirected → unknown
7cebcfd4071c -
Доступність
Доступність: unknown → redirected
1d472e8e6a2f -
Збережене спостереження
Збережене спостереження: alive → dead
-
Доступність
Доступність: redirected → unknown
ca255b61650a -
Збережене спостереження
Збережене спостереження: dead → alive
Показати всі (1)
-
Доступність
Доступність: unknown → redirected
ee387efd9a9e
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of kra39at.com · checked Mar 27, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога