kra37cc-kra38cc[.]ru
“kra37 cc, kra38 cc официальная ссылка по землеройным работам и услугам спецтехники”
kra37cc-kra38cc.ru — 内容不可用. 品牌冒充:Kraken; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 2/95 (SOCRadar, Webroot); PhishDestroy score 56/100. 注册商: DOMENUS-RU.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of kra37cc-kra38cc.ru confirms it was a brand-impersonation domain targeting Kraken, the cryptocurrency exchange. The domain, registered on August 31, 2025, through DOMENUS-RU, resolved to 172.67.190.44, a Cloudflare IP (AS13335) located in the US. No SSL certificate was present, increasing the risk of plaintext credential interception. The page title, 'kra37 cc, kra38 cc официальная ссылка по землеройным работам и услугам спецтехники,' is anomalous for a cryptocurrency platform, suggesting either misdirection or a placeholder during development.
Nameservers dax.ns.cloudflare.com and magdalena.ns.cloudflare.com indicate Cloudflare hosting, a common tactic to obscure origin infrastructure. The domain appeared on one security blocklist (PhishDestroy) and was flagged by 2 of 95 vendors on VirusTotal, though the specific detection engines and signatures are not detailed in available intelligence. Gridinsoft assigned a trust score of 0/100, consistent with confirmed malicious domains. As of the report date, the domain is offline, likely following takedown action.
Defenders should treat any residual DNS queries or cached references to this domain as indicators of compromise (IOCs). While the exact phishing kit or payload is not confirmed, the combination of Kraken impersonation, Cloudflare obfuscation, and absence of SSL aligns with credential-harvesting campaigns targeting cryptocurrency users. Network defenders are advised to block the domain, IP, and associated nameservers at perimeter controls and monitor for related infrastructure reuse under new domains.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。