kra46-cc[.]filippok-langepas[.]ru
“kra46 - CC инновации в управлении проектами”
kra46-cc.filippok-langepas.ru — Контент недоступний. Зведення доказів: VirusTotal 14/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); Google Safe Browsing flagged; PhishDestroy score 92/100. Реєстратор: REGRU-RU.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of kra46-cc.filippok-langepas.ru shows a high‑risk credential harvesting infrastructure that was taken offline prior to the report date of July 24, 2026. The domain resolves to the public IPv4 address 193.105.134.30, which is registered to AS42237 (w1n ltd) in Sweden. Registration data indicates the domain was created on December 10, 2024 through the Russian registrar REGRU-RU. No TLS certificate is presented, meaning the site served only over HTTP, a common trait of low‑cost phishing deployments.
The page title returned by the host is "kra46 - CC инновации в управлении проектами," providing no direct indication of the targeted brand or service. Trust scoring from Gridinsoft assigns a zero out of one hundred, reflecting an extremely low reputation. The domain appears on a single security blocklist and is actively blocked by the PhishDestroy service. Google Safe Browsing classifies the URL as social engineering, and VirusTotal records 14 detections out of 95 scanned scanners, confirming malicious intent.
Nameserver delegation points to ns1.armadns.icu and ns2.armadns.icu, both of which are frequently associated with disposable or fast‑flux hosting. Current DNS queries show the domain as offline, suggesting the operators have withdrawn the site or are rotating infrastructure. Defenders should continue to block the domain at perimeter and DNS layers, monitor the associated IP 193.105.134.30 for any resurgence, and add the nameservers to watchlists for future abuse. Because the site lacks SSL and the page content is not publicly available, further forensic capture is not possible, and the primary mitigation remains proactive blocking and threat‑intel sharing.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога