Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@iqweb.io.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
krab--5----cc[.]ru
“Krab5 CC | Онлайн агрегатор по созданию сайтов!”
krab--5----cc.ru — Неперевірений. Уособлення бренду: Kraken; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 2/93 (Gridinsoft, SOCRadar); PhishDestroy score 56/100. Реєстратор: RU-CENTER-RU.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of krab--5----cc.ru shows a confirmed brand‑impersonation campaign targeting the cryptocurrency exchange Kraken. The domain was registered on 21 February 2026 through RU‑CENTER‑RU and resolves to IP 186.2.175.37, which is announced by AS59692 (IQWeb FZ‑LLC) and geolocated to Belarus. The host returns HTTP 502, indicating the web service is currently unavailable, and the site is marked as offline. A Let’s Encrypt R12 certificate covers the domain, confirming TLS is in use despite the service disruption. Cloudflare nameservers (marjory.ns.cloudflare.com and terry.ns.cloudflare.com) are configured, suggesting the operators leveraged Cloudflare’s CDN and DNS protection.
The page title discovered during a prior fetch reads “Krab5 CC | Онлайн агрегатор по созданию сайтов!”, a generic Russian‑language phrase that does not reference Kraken, but the documented scam type explicitly lists brand impersonation of Kraken. Technical footprints include Yandex.Metrika analytics and DDoS‑Guard protection, both common in malicious Russian‑hosted sites. VirusTotal scans flagged the domain by 2 of 93 vendors, and Gridinsoft assigns a trust score of 0 / 100. Independent blocklists and security services (PhishDestroy, MetaMask, SEAL) have already listed the domain, and it appears on three additional blocklists.
The combination of low trust scoring, vendor detections, and active blocklisting indicates a high probability of malicious intent. Uncertainty remains around the exact payload or credential‑harvesting mechanisms because the site is offline and no page content has been captured. Defenders should continue to block the domain at perimeter and DNS layers, monitor the hosting IP for related activity, and update incident response playbooks to include Kraken‑related impersonation vectors. Threat intelligence feeds should be refreshed with the domain’s identifiers to ensure rapid detection of any re‑use of the same infrastructure.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Yandex.Metrica is a free web analytics service that tracks and reports website traffic.
metrika.yandex.com 100% впевненостіDDoS-Guard is a Russian Internet infrastructure company which provides DDoS protection, content delivery network services, and web hosting services.
ddos-guard.net 100% впевненостіАналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of krab--5----cc.ru · checked Mar 6, 2026
Докази та зовнішні звіти
PD-20260202-91B0BD Recipient: abuse@iqweb.io Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога