Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
kra39-at[.]cc
“KRA39.cc - KRA39.at”
kra39-at.cc — 未验证. 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 1 alert; PhishDestroy score 95/100. 注册商: NiceNIC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain kra39-at.cc was registered on 19 January 2025 through NICENIC INTERNATIONAL GROUP CO., LIMITED. It is hosted behind Cloudflare, as indicated by the authoritative nameservers shaz.ns.cloudflare.com and yadiel.ns.cloudflare.com, and resolves to the Cloudflare‑owned address 104.21.81.180 located in Canada. The site presents a page title “KRA39.cc - KRA39.at”, suggesting a possible attempt to mimic a legitimate brand or service.
Analysis classifies the site as a generic phishing infrastructure. The domain appears on a single security blocklist and is explicitly blocked by PhishDestroy, confirming its malicious intent. The HTTP response is a 301 redirect, which is commonly used to forward victims to credential‑harvesting pages while obscuring the original URL. The presence of Cloudflare Browser Insights and HTTP/3 indicates that the operators are leveraging modern CDN features to improve performance and evade detection.
VirusTotal scans have flagged the domain in 15 of 95 security vendor checks, and Gridinsoft assigns a trust score of 0 out of 100, reinforcing the high‑risk assessment. The TLS certificate is issued by Google Trust Services under the WE1 designation, which is typical for Cloudflare‑proxied sites and does not provide any reassurance about the underlying content. The combination of a high‑risk blocklist status, low trust score, and multiple vendor detections points to an active phishing campaign.
Defenders should add kra39-at.cc to network‑level deny lists and block outbound connections to its resolving IP 104.21.81.180. Monitoring for any HTTP 301 redirects to this domain can help identify compromised clients attempting to contact the site. Since the infrastructure relies on Cloudflare, threat‑intel feeds that track Cloudflare‑hosted malicious domains should be consulted regularly for any related indicators. Continuous re‑evaluation is advised because the domain remains active and may evolve its tactics.
网络安全情报 Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | kra39-at.cc |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
Latest Classified Outcome 2026-08-15 02:43:16 UTC
所用技术 · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of kra39-at.cc · checked Mar 27, 2026
网站配置分析
证据与外部报告
PD-20260326-0FA79D Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。