kra39web[.]cc
Перевірка домену kra39web.cc на фішинг і безпеку
“kra46.cc”
kra39web.cc — Контент недоступний (HTTP 502). Зведення доказів: VirusTotal 4/93 (alphaMountain.ai, Forcepoint ThreatSeeker, SOCRadar, Webroot); PhishDestroy score 65/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis as of July 24 2026 indicates that the domain kra39web.cc is offline but was previously identified as a phishing infrastructure. The domain was registered on February 21 2026 and resolves to the IP address 172.67.170.146, which belongs to AS13335 operated by Cloudflare, Inc. The hosting location is the United States. The TLS certificate presented by the site is identified as “WE1”. VirusTotal scans show that four out of ninety‑three security vendors flagged the domain as malicious, providing independent corroboration of its suspicious nature.
The domain appears on a single blocklist, specifically PhishDestroy, confirming that at least one external mitigation service has taken action to block it. The HTTP response returned a page title of “kra46.cc”, which does not match the registered domain and is a typical indicator of a mismatched or spoofed landing page. No additional intelligence such as Safe Browsing, OTX, or registrar reputation is available in the current dataset. Because the site is currently taken offline, immediate traffic to the IP address is unlikely, but the underlying hosting provider (Cloudflare) may be reused for future malicious campaigns.
Defenders should continue to monitor the IP 172.67.170.146 for any re‑appearance of malicious content, enforce blocklist entries that reference kra39web.cc, and consider adding the domain to internal deny lists. Network sensors should be configured to alert on DNS queries for kra39web.cc and any rapid resolution changes. Given the limited blocklist coverage (one list) and the modest detection count, further verification through dynamic analysis or sandboxing is recommended if the domain becomes active again. Maintaining up‑to‑date threat intel feeds that include Cloudflare‑hosted malicious actors will reduce exposure to repeat use of this infrastructure.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога