kra-43-cc-at[.]ru
“Kra43 CC — твой вкус AT”
kra-43-cc-at.ru — 内容不可用. 证据摘要: VirusTotal 14/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; PhishDestroy score 92/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain is flagged as a high-risk phishing threat specifically targeting users of Kra43 CC, a payment portal service. Analysis indicates the site employs generic phishing tactics to harvest credentials or financial data, likely through a fake login or transaction interface. The page title, 'Kra43 CC — твой вкус AT,' suggests an attempt to mimic legitimate Kra43 CC branding while using localized language to increase credibility. Infrastructure analysis reveals the domain was registered through Cloudflare, Inc., and currently resolves to the IP address 193.105.134.74, hosted on AS42237 (w1n ltd) in Sweden. VirusTotal reports 14 out of 95 security vendors flagging the domain as malicious, while Google Safe Browsing and one additional security blocklist have also marked it as phishing. The domain lacks an SSL certificate, further reducing its legitimacy. Registration details and hosting provider data align with patterns observed in short-lived phishing campaigns. Mitigation steps for this threat include immediate blocking of the domain and its associated IP (193.105.134.74) at the network perimeter. Organizations should deploy web filtering rules to prevent access to kra-43-cc-at.ru and monitor for any attempts to reach it from internal systems. End-users should be alerted to verify payment portals directly through official Kra43 CC channels, avoiding links from emails or third-party sites. Security teams are advised to check logs for connections to 193.105.134.74 or the domain within the past 48 hours, as this aligns with typical phishing campaign lifecycles.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。