kra47-at[.]cc
“Captcha”
kra47-at.cc — Неперевірений. Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 2 alerts; PhishDestroy score 95/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain kra47-at.cc is currently identified as a credential theft operation designed to harvest user login credentials through deceptive web interfaces. Analysis indicates the domain is presently offline, though prior activity suggests it was actively deployed in campaigns targeting unsuspecting users. The page title "Captcha" is a common tactic to lend false legitimacy, often used to bypass initial suspicion while capturing sensitive authentication details. Infrastructure analysis reveals the domain was flagged by 9 of 95 security vendors on VirusTotal, indicating a high-confidence malicious classification. It was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on March 26, 2026, an unusually future-dated creation that may suggest domain spoofing or registry manipulation. The domain resolves to the IP address 188.114.97.3, hosted by a content delivery network in Canada, which is frequently leveraged to obscure origin infrastructure. The SSL certificate, issued by Google Trust Services (WE1), does not mitigate the threat, as malicious actors routinely exploit trusted certificate authorities. The domain appears on one security blocklist, and its activity was previously blocked by enterprise-grade filtering systems. Current status confirms kra47-at.cc has been taken offline, likely due to detection and mitigation efforts. However, the underlying threat remains elevated due to the domain’s recent registration anomaly and the use of infrastructure commonly associated with credential theft operations. Organizations and users are advised to block the domain and IP at the network perimeter, monitor for related indicators of compromise, and implement multi-factor authentication to mitigate credential exposure. Security teams should review logs for prior connections to 188.114.97.3 or interactions with the domain, particularly those involving login prompts or captcha requests, as these are primary indicators of compromise.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Latest Classified Outcome 2026-08-13 02:43:13 UTC
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of kra47-at.cc · checked Mar 27, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога