kra46-cc-s[.]ru
“Kra46 CC | Подборка ночного света: мягко, безопасно, красиво”
kra46-cc-s.ru — 未验证. 诈骗类型:Crypto Drainer. 证据摘要: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, CRDF, Gridinsoft, SOCRadar); PhishDestroy score 71/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of kra46-cc-s.ru shows a newly registered domain (created 28 March 2026) that is currently active and classified as a high‑risk crypto drainer. The host returns an HTTP 301 redirect and presents a TLS certificate issued by Let’s Encrypt (E8), indicating encrypted traffic. DNS resolution points to 188.114.97.3, an address owned by CloudFlare, Inc. in Canada. The page title “Kra46 CC | Подборка ночного света: мягко, безопасно, красиво” is the only visible content; no additional page content has been examined. VirusTotal reports three detections out of ninety‑four scanners, and the domain appears on a single security blocklist. Independent monitoring services such as PhishDestroy have already blocked the host, and Gridinsoft assigns a trust score of zero out of one hundred. The evidence suggests the infrastructure is being used to lure victims into cryptocurrency‑related scams, although the exact phishing lure or compromised accounts have not been disclosed. Defenders should add the domain and its IP address to outbound and inbound filtering rules, monitor TLS connections to the Let’s Encrypt certificate, and enforce URL reputation checks that incorporate the current blocklist entries. Continuous re‑scanning is recommended to capture any new detections, and any observed traffic should be logged for forensic correlation with potential crypto‑drain incidents.
威胁响应 Pipeline
公共封禁名单状态
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。