krk44[.]at
“Krа47.at | Krа47.cc - Проверка браузера - krab1.cc | krab1.at”
Зведення доказів
Analysis of krk44.at indicates a high‑confidence malicious profile despite the domain being taken offline at the time of review. The site previously responded with HTTP 200, and its SSL certificate was issued to PhishDestroy / botadmin.destroy.tools, a known indicator of phishing infrastructure. The certificate and the fact that the domain resolves to 172.67.222.128, an address owned by AS13335 Cloudflare, Inc., suggest the operators leveraged Cloudflare’s CDN and DNS services (luke.ns.cloudflare.com and rosalie.ns.cloudflare.com) to obscure the true hosting location. The registrar listed is Hosting Concepts B.V. d/b/a Registrar.eu, which is a legitimate registrar but does not mitigate the malicious intent observed.
Gridinsoft assigned a trust score of 0 / 100, effectively flagging the domain as completely untrusted. The page title captured during the brief availability – “Krа47.at | Krа47.cc - Проверка браузера - krab1.cc | krab1.at” – contains Russian text referring to a “browser check” and references to krab1, a pattern seen in other crypto‑drainer campaigns that use language obfuscation to evade detection. The domain appears on one security blocklist and was flagged by four of ninety‑three VirusTotal scanners, reinforcing the suspicion of abuse. The identified scam type is a Crypto Scam, consistent with the observed indicators.
Defenders should immediately block krk44.at at perimeter firewalls and DNS resolvers, monitor for any re‑registration of the same name or related subdomains, and consider adding the associated IP range (172.67.222.128) to threat‑intel feeds. Continuous observation of Cloudflare‑associated IPs used by the domain is advised, as the actors may shift infrastructure while retaining the same CDN front‑end.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
VirusTotal
4 → 7
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога