kra34cc[.]vip
“Captcha”
kra34cc.vip — 隐形 · 可达 (HTTP 502). 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 8/94 (ADMINUSLabs, alphaMountain.ai, CRDF, Fortinet, G-Data); cloaking observed; PhishDestroy score 78/100. 注册商: NiceNIC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies kra34cc.vip as an active credential harvesting domain posing an elevated risk to visitors. This recently created domain operates as a generic phishing site, likely designed to impersonate legitimate services and trick users into submitting login credentials. Security researchers and end-users should treat this domain with high caution, as it exhibits multiple red flags consistent with malicious activity targeting unsuspecting victims. This domain was flagged by 3 out of 95 VirusTotal security vendors, indicating limited but notable detection of its malicious nature. It is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar known for hosting dynamic and often abusive registrations. kra34cc.vip resolves to IP address 104.21.48.157, a hosting provider frequently associated with phishing campaigns. The domain was created on June 03, 2025, making it extremely new and untrusted. Despite a valid SSL certificate issued by Google Trust Services—commonly abused by threat actors to appear legitimate—there are no indicators of legitimate use. This domain remains unlisted on major threat intelligence blocklists as of the latest scan, suggesting rapid deployment and currently low exposure in global defenses. Users who encounter kra34cc.vip should immediately refrain from interacting with the site, especially avoid entering any login credentials, personal information, or payment details. Given the domain’s recent registration and low but critical detection rate, it is likely targeting unsuspecting users with fake login portals. To verify site safety and confirm this domain’s malicious status, users should consult PhishDestroy’s threat lookup tool before proceeding. Organizations are advised to block access to 104.21.48.157 at the network level and update firewall rules to prevent outbound connections. Always report suspicious domains to threat intelligence platforms to enhance collective defense against credential harvesting campaigns.
网络安全情报 Registrar context
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-08 04:02:22 UTC
所用技术 · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of kra34cc.vip · checked Mar 29, 2026
证据与外部报告
PD-20260329-310E9E Recipient: abuse@nicenic.net, abuse@mmx.co, compliance@icann.org 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。