Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
kra39at[.]com
“Kra39.at – Рабочее зеркало kra39”
Quan sát đã lưu
Độ tương phản tiêu đề quan sát được
PhishDestroy identifies kra39at.com as an active crypto-draining phishing domain designed to trick visitors into approving malicious wallet transactions that silently transfer their cryptocurrency to attacker-controlled addresses. When loaded, the page mimics a legitimate crypto service login or token swap interface, prompting users to connect their wallets or sign transactions that drain funds instead of executing the promised swap or withdrawal. This type of attack is called a crypto drainer and is one of the fastest-growing threats in Web3, often embedded on malicious ads, fake airdrop sites, or hijacked social-media accounts. This domain was flagged by PhishDestroy as a crypto drainer on November 03, 2024, the same day it was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. Security vendor scans via VirusTotal indicate that 2 out of 95 engines detect malicious activity associated with kra39at.com. The site resolves to IP address 188.114.97.3 and holds an SSL certificate issued by Google Trust Services, which attackers often use to appear legitimate. Due to the low detection rate, the domain currently carries an elevated risk level, meaning it can evade some automated filters and reach real users. If you visited kra39at.com, disconnect your wallet immediately and revoke any permissions you may have granted. Never sign wallet transactions from unknown sites, and enable transaction simulation tools or hardware wallet confirmations to block unauthorized transfers. Clear your browser cache and cookies, and consider running a malware scan on your device. Report the domain to your wallet provider and to PhishDestroy to help protect others. Share this warning on social platforms or crypto forums to raise awareness and prevent further victims.
Bản ghi báo cáo đã gửi
Ảnh chụp bằng chứng đã gửi
- Đã gửi
- Bản ghi sổ cái
- 1
- Mã vụ việc
PD-20260327-17D09B- Tiêu đề trang đã chụp
- Kra39.at – Рабочее зеркало kra39
- Tệp PDF
- Bằng chứng PDF
Toàn văn bằng chứng
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Tình báo an ninh mạng Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | kra39at.com |
malicious | Sinkholed |
Pipeline ứng phó với các mối đe dọa
Phạm vi danh sách chặn
10 nguồn · đồng bộ ngày 10/08/2026
Dòng thời gian phát hiện
Các quan sát đã lưu theo thứ tự thời gian.
-
Khả dụng
Khả dụng: lần đầu được quan sát là unknown
993d00c35140 -
Khả dụng
Khả dụng: unknown → live_content
f5732ac012ee -
Khả dụng
Khả dụng: live_content → redirected
f45e1297c3c6 -
Khả dụng
Khả dụng: redirected → unknown
145f0224b9f5 -
Khả dụng
Khả dụng: unknown → redirected
12a141bf6c19 -
Khả dụng
Khả dụng: redirected → unknown
7cebcfd4071c -
Khả dụng
Khả dụng: unknown → redirected
1d472e8e6a2f -
Quan sát đã lưu
Quan sát đã lưu: alive → dead
-
Khả dụng
Khả dụng: redirected → unknown
ca255b61650a -
Quan sát đã lưu
Quan sát đã lưu: dead → alive
Hiển thị tất cả (1)
-
Khả dụng
Khả dụng: unknown → redirected
ee387efd9a9e
Bản chụp đã lưu
Thông tin về tên miền
Chi tiết kỹ thuậtDNS, tên TLS và mốc thời gian
ICANN OVERSIGHT
Bối cảnh công nhận và RAA
Bối cảnh công nhận và RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Phân tích của VirusTotal
Phân tích hiệu suất trang
Google PageSpeed Insights — mobile performance audit of kra39at.com · checked Mar 27, 2026
Bạn có bị ảnh hưởng bởi trang web này không?
Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.
Hãy báo cáo với chính quyền địa phương
Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.
Kiểm tra bất kỳ tên miền nào
Phân tích mối đe dọa bằng cách sử dụng danh sách chặn được lưu trữ, WHOIS, DNS và bằng chứng quét công khai
Quét ngayBáo cáo lừa đảo qua email
Hãy gửi các tên miền đáng ngờ đến cơ sở dữ liệu mối đe dọa của chúng tôi — để bảo vệ cộng đồng
Báo cáoDòng tin tức về các mối đe dọa thời gian thực
Các báo cáo lừa đảo gần đây và những thay đổi về tính khả dụng được quan sát thấy
Theo dõiLuôn cập nhật thông tin, luôn an toàn
Theo dõi các mối đe dọa đang diễn ra hoặc phản đối danh sách này nếu bạn cho rằng đây là kết quả báo động sai