kra--36---------cc[.]ru
“kra46 - CC академия архитектуры снов”
kra--36---------cc.ru — 内容不可用. 证据摘要: VirusTotal 15/95 (ADMINUSLabs, alphaMountain.ai, Bfore.Ai PreCrime, BitDefender, CyRadar); Google Safe Browsing flagged; PhishDestroy score 95/100. 注册商: REGRU-RU.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, kra--36---------cc.ru, operates as a high-risk credit card phishing infrastructure designed to harvest financial credentials through deceptive theming. The site presents itself as "CC академия архитектуры снов" (CC Academy of Dream Architecture), a fabricated entity likely intended to exploit trust in educational or professional branding. Analysis indicates the domain specifically targets payment card details, a common objective in credential phishing campaigns where attackers mimic legitimate services to trick users into submitting sensitive information. The use of Cyrillic characters and financial-themed keywords suggests an attempt to evade casual scrutiny while appealing to a specific demographic. Infrastructure analysis reveals multiple indicators of malicious intent. The domain was registered on August 7, 2025, through REGRU-RU, a registrar frequently associated with phishing operations. It resolves to the IP address 193.105.134.30, hosted on AS42237 (w1n ltd) in Sweden, an autonomous system previously linked to fraudulent activities. Security vendors flagged the domain in 15 out of 95 detections on VirusTotal, while it appears on one additional blocklist. The absence of an SSL certificate further undermines its legitimacy, as modern phishing sites typically employ encryption to appear credible. Google Safe Browsing and PhishDestroy have independently classified this domain as phishing, corroborating its malicious classification. Users who visited kra--36---------cc.ru should take immediate remedial action. If any credentials or payment details were entered, affected parties must contact their financial institutions to monitor for unauthorized transactions and request card reissuance if necessary. System scans using updated security tools are recommended to detect potential malware or browser-based exploits. Browser caches and saved passwords should be cleared to eliminate residual session data. Given the domain's recent creation and targeted nature, vigilance for follow-up phishing attempts via email or messaging platforms is advised. Organizations should update their blocklists to include this domain and its associated IP address to prevent future access.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。