kraken6at[.]net
“KRAKEN”
kraken6at.net — Помилка сервера (HTTP 502). Уособлення бренду: Kraken; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, CRDF, Forcepoint ThreatSeeker, Gridinsoft); URLQuery 2 alerts; PhishDestroy score 70/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies kraken6at.net as a crypto drainer domain impersonating the legitimate Kraken cryptocurrency exchange platform. This fraudulent site employs branding mimicry to deceive users into connecting cryptocurrency wallets under the false pretense of offering exchange services or promotions. The domain specifically targets users familiar with Kraken's services, exploiting trust in the brand to facilitate unauthorized cryptocurrency transfers through wallet-draining mechanisms. Security researchers have documented active campaigns where threat actors distribute links to this domain via phishing emails, social media messages, or fraudulent advertisements, typically promising exclusive offers or account verification processes to lure victims into connecting their wallets. Once connected, the site initiates unauthorized transactions that drain digital assets without user consent. This domain was flagged by 5 out of 95 leading security vendors on VirusTotal, indicating partial detection coverage but not universal recognition as malicious. The domain kraken6at.net was registered on April 4, 2025, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar known for accommodating high-risk domain registrations. The site operates using an SSL certificate issued by Google Trust Services, likely to appear legitimate and evade browser security warnings. It resolves to the IP address 188.114.97.3, which has been associated with previous cryptocurrency-related fraud campaigns. The relatively recent creation date and low detection rate suggest this is a newly deployed threat actor infrastructure designed to evade early-stage detection systems. Users who have visited kraken6at.net or entered any information should immediately disconnect their cryptocurrency wallets and revoke any connected permissions through their wallet provider's interface. Monitor blockchain transactions for unauthorized transfers and report any fraudulent activity to the respective wallet provider and cryptocurrency exchange. PhishDestroy recommends scanning all devices used for cryptocurrency transactions with updated antivirus software to detect potential malware that may have been installed during the visit. Report this domain to PhishDestroy's database to enhance collective threat intelligence and prevent further victimization. Users should always verify the legitimacy of cryptocurrency-related websites by checking official Kraken domains (kraken.com) and enabling two-factor authentication on all exchange accounts.
Розвіддані з мережевої безпеки Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | kraken6at.net |
malicious | Sinkholed |
| Hagezi Threat Feed | kraken6at.net |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-14 02:48:12 UTC
Технології · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of kraken6at.net · checked Mar 29, 2026
Докази та зовнішні звіти
PD-20260328-8FD99A Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога