Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
at-krab9[.]cc
“krab9.cc”
at-krab9.cc — 最后已知的活跃状态 (HTTP 200). 诈骗类型:Crypto Drainer. 证据摘要: VirusTotal 6/91 (alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, SOCRadar); Spamhaus DBL_PHISH; PhishDestroy score 80/100. 注册商: NiceNIC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies at-krab9.cc as an active crypto-drainer domain registered on December 11, 2025 and currently resolving to IP 188.114.96.3. Security telemetry confirms this host serves credential-harvesting and wallet-draining payloads under the guise of fake job offers, classified as a generic phishing threat with elevated risk. The domain leverages social-engineering tactics to trick victims into connecting crypto wallets and signing malicious transactions that silently drain balances.
Technical indicators for this domain are conclusive: VirusTotal detection score is 3/95 security vendors; domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED; SSL certificate issued by Google Trust Services is active; first seen on December 11, 2025; and the IP address 188.114.96.3 is shared across multiple high-risk campaigns. Current blocklist coverage remains low, suggesting rapid propagation before widespread takedown.
At the time of analysis, at-krab9.cc remains active and is actively distributing malicious JavaScript payloads targeting cryptocurrency users. Immediate network block at DNS and IP levels is recommended, alongside user advisories to avoid job-offer links from unsolicited messages. Despite active takedown efforts, residual risk persists due to the domain’s recent registration and shared infrastructure, warranting continuous monitoring and proactive blocking.
网络安全情报 Registrar context
威胁响应 Pipeline
公共封禁名单状态
Latest Classified Outcome 2026-08-14 02:39:22 UTC
所用技术 · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of at-krab9.cc · checked Mar 29, 2026
证据与外部报告
PD-20260328-2E4499 Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。