kraklink[.]cc
“kraklink.cc”
Зведення доказів
This domain, kraklink.cc, is identified as a credential theft phishing site targeting unsuspecting users through deceptive login interfaces. Analysis indicates no direct association with a specific brand or cryptocurrency drainer kit, but the infrastructure aligns with known credential harvesting tactics. The site employs social engineering to trick users into submitting sensitive information, such as usernames, passwords, and potentially multi-factor authentication codes, which are then exfiltrated to attacker-controlled servers. Infrastructure analysis reveals the domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on March 29, 2026, an unusually forward-dated registration that may indicate an attempt to evade immediate detection. The domain resolves to the IP address 86.54.25.38, a host with no prior reputation for legitimate services. At the time of assessment, 14 out of 95 security vendors on VirusTotal flagged kraklink.cc as malicious, while Gridinsoft assigned a trust score of 0/100. The domain appears on a single security blocklist, and its SSL certificate is issued by Let's Encrypt, a common tactic among threat actors to mimic legitimacy. As of the latest verification, kraklink.cc has been taken offline, likely in response to detection by security mechanisms. However, the infrastructure remains a residual risk, as the domain could be reactivated or repurposed for future campaigns. Users who interacted with the site are advised to reset credentials immediately, particularly for accounts accessed during the exposure window. Organizations should monitor network logs for connections to 86.54.25.38 and consider blocking the domain and IP at the perimeter to prevent potential re-emergence of this threat.
Data Coverage
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | kraklink.cc |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 10.08.2026
Хронологія виявлення
-
VirusTotal
12 → 14
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога