kra30-att[.]cc
“kra30-att.cc”
kra30-att.cc — 隐形 · 可达. 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 15/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLQuery 2 alerts; Spamhaus DBL_PHISH; cloaking observed; PhishDestroy score 100/100. 注册商: NiceNIC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
kra30-att.cc is an active domain engaging in credential theft, posing a significant risk to users attempting to enter sensitive login information. This domain is currently operational and should be treated as a threat due to its malicious intent targeting user credentials.
The domain was registered on July 10, 2025, through NICENIC INTERNATIONAL GROUP CO., LIMITED and resolves to the IP address 185.226.92.168. VirusTotal scanning shows that 15 out of 95 security vendors have flagged kra30-att.cc as malicious. The domain holds an SSL certificate issued by Let's Encrypt, and it appears on one known security blocklist. Additionally, the domain is blocked by OISD, indicating community recognition of its threat.
At present, kra30-att.cc remains active and continues to pose a threat to users by attempting to steal credentials. It is highly recommended to block access to this domain at the network level and educate users to avoid interacting with any communications referencing this site. Monitoring for related threat indicators and updating security controls accordingly will help mitigate potential credential compromise.
网络安全情报 Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | kra30-att.cc |
malicious | Sinkholed |
| DNS4EU | kra30-att.cc |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
Latest Classified Outcome 2026-08-15 02:43:47 UTC
所用技术 · 2 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
VirusTotal 分析
存档证据
证据与外部报告
PD-20260326-717B78 Recipient: abuse@bigcore.net 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。