www-kra8[.]cc
“www-kra8.cc”
www-kra8.cc — Неперевірений. Уособлення бренду: Kraken; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 5/94 (ADMINUSLabs, alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet); Spamhaus DBL_PHISH; PhishDestroy score 65/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies www-kra8.cc as an active crypto drainer scam site, designed to steal cryptocurrency from unsuspecting victims. This domain masquerades as a legitimate exchange, leveraging deceptive branding to trick users into connecting wallets or entering sensitive credentials. The infrastructure and naming convention (e.g., 'kra8' mimicking 'Kraken') suggest a targeted campaign against cryptocurrency traders, with a focus on draining funds via fraudulent transaction prompts.
Technical analysis of www-kra8.cc reveals alarming red flags: the domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar often exploited by threat actors for disposable infrastructure. Resolving to IP 86.54.25.38, the domain exhibits a brief operational window, having been created on December 09, 2024. VirusTotal confirms its malicious nature, with 4 out of 95 security vendors detecting its threat. While no direct association with Google Safe Browsing (GSB) was observed in this dataset, the domain’s low VT detection ratio suggests it may evade some defenses, increasing its potential impact. Blocklists, including those monitored by PhishDestroy, have flagged this domain multiple times, reinforcing its elevated risk profile.
As of the latest analysis, www-kra8.cc remains active and poses a significant threat to cryptocurrency users. Immediate actions include blocking the domain at the network and endpoint levels, flagging the associated IP (86.54.25.38) for takedown or isolation, and disseminating user advisories to raise awareness. Mitigation strategies should prioritize blocking the domain via DNS filtering, monitoring for outbound connections to the IP, and updating threat intelligence feeds to include this indicator. The remaining risk is elevated due to the domain’s recent creation, low VT detection rate, and active status, warranting continuous monitoring and proactive defense measures to prevent financial losses.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Latest Classified Outcome 2026-08-16 02:49:48 UTC
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога