kra-b5cc[.]ru
“slon5.cc”
证据摘要
PhishDestroy identifies kra-b5cc.ru as an active crypto drainer domain masquerading under a spoofed branding scheme. Registered through REGRU-RU on January 28, 2026, this domain resolves to IP 172.67.149.212 and utilizes a Let's Encrypt SSL certificate, suggesting an attempt to establish false legitimacy. While no specific drainer kit has been publicly attributed, the domain's naming convention (kra- prefix) indicates likely impersonation of a major exchange or wallet service, a common tactic in crypto drainer campaigns to deceive users into connecting malicious wallets or entering seed phrases.
Technical indicators confirm high-risk attributes: VirusTotal currently reports 0/95 detections, indicating evasion of mainstream security engines, while the domain remains unflagged in Google Safe Browsing (GSB) as of the latest scan. The registration occurred just days ago, suggesting a freshly deployed threat designed to capitalize on low historical reputation. With no presence on major blocklists (0 detected), this domain poses an elevated risk to unsuspecting cryptocurrency users who may interact with fraudulent links or QR codes promoted via social engineering.
As of the latest intelligence, kra-b5cc.ru remains active and under investigation, with no confirmed takedown or mitigation by hosting providers. Immediate actions include blocking the domain at DNS and network levels, flagging the IP 172.67.149.212, and monitoring for associated wallet addresses or drainer payloads. Users should avoid clicking any links or scanning QR codes associated with this domain, and organizations are advised to deploy custom blocklists and user awareness training. Remaining risk is high due to low detection rates and recent deployment, warranting heightened vigilance until remediation occurs.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
技术
识别出 3 项高置信度技术
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of kra-b5cc.ru · checked May 9, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控