krab5cc-5[.]ru
“Slon2at — люди, которые добровольно живут без интернета”
Зведення доказів
Analysis of the domain krab5cc-5.ru indicates it is an active phishing infrastructure with elevated risk as of July 29, 2026. The domain was registered on March 7, 2026, through REGRU-RU, a registrar previously associated with malicious campaigns. Its nameservers, ns1.reg.ru and ns2.reg.ru, further link it to the same provider, suggesting centralized control of the hosting environment. The domain resolves to the IP address 205.185.113.136, which has been observed in prior phishing operations, though no specific autonomous system or geolocation details are currently available for this address. Detection metrics reveal limited but concerning visibility.
The domain appears on one security blocklist, specifically PhishDestroy, which classified it as malicious. On VirusTotal, two of ninety-one security vendors flagged the domain, indicating early but growing recognition of its threat status. No additional context regarding the specific brand impersonated, phishing kit employed, or exact content hosted is available at this time, as the page title and targeted entity remain unconfirmed. The domain's classification as 'generic phishing' suggests it may be part of a broader, non-brand-specific campaign, though this cannot be definitively established without further analysis.
Defenders should treat this domain as an active threat. Network-level blocking of both the domain and its resolving IP (205.185.113.136) is recommended for organizations using PhishDestroy or similar detection feeds. Given the domain's recent registration and limited detection footprint, monitoring for additional blocklist inclusions or vendor detections over the coming days may provide further clarity on its scope and intent. No evidence currently links this domain to advanced persistent threats or targeted attacks, but its infrastructure aligns with opportunistic phishing operations observed in prior campaigns.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
Хронологія виявлення
-
Статус домену
Доступний → Недоступний
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога