kra44at[.]cc
“krab2.cc — krab2.at | Рабочая ссылка для входа 2025”
证据摘要
On July 25, 2026, investigators observed that the domain kra44at.cc is currently offline but remnants of its infrastructure remain relevant for threat‑intel monitoring. The domain was registered on October 12, 2025 through Internet Domain Service BS Corp. and is delegated to the Cloudflare nameservers cash.ns.cloudflare.com and kallie.ns.cloudflare.com. DNS resolution points to the public IP address 188.114.97.3, which belongs to AS13335 Cloudflare, Inc. and is geolocated to the United States. No TLS certificate was presented for the host, indicating that the site operated without HTTPS protection.
The only visible artifact is the page title “krab2.cc — krab2.at | Рабочая ссылка для входа 2025”, which suggests the site was presenting a Russian‑language login link for the year 2025. No additional branding or target organization is disclosed in the captured metadata, and the page content has not been harvested for visual analysis. Scanning on VirusTotal returned three positive detections out of ninety‑three submitted security vendors, confirming that at least a minority of AV engines recognized the domain as malicious. The domain appears on a single external blocklist and has been explicitly flagged by the PhishDestroy service.
Independent reputation scoring from Gridinsoft assigns a trust score of 0 out of 100, reinforcing the classification of the host as highly suspicious. Given the combination of a recent registration date, Cloudflare‑hosted infrastructure, lack of TLS, low trust rating, and multiple vendor detections, the domain fits the pattern of a short‑lived phishing or credential‑harvesting site. Defenders should add kra44at.cc to internal block and monitoring lists, ensure that any outbound connections to the associated IP address are logged, and verify that security‑aware users are warned about unsolicited login prompts that reference the Russian phrase “Рабочая ссылка для входа”.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
检测时间线
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控