kra47-at[.]cc
“Captcha”
kra47-at.cc — 未验证. 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 2 alerts; PhishDestroy score 95/100. 注册商: NiceNIC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain kra47-at.cc is currently identified as a credential theft operation designed to harvest user login credentials through deceptive web interfaces. Analysis indicates the domain is presently offline, though prior activity suggests it was actively deployed in campaigns targeting unsuspecting users. The page title "Captcha" is a common tactic to lend false legitimacy, often used to bypass initial suspicion while capturing sensitive authentication details. Infrastructure analysis reveals the domain was flagged by 9 of 95 security vendors on VirusTotal, indicating a high-confidence malicious classification. It was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on March 26, 2026, an unusually future-dated creation that may suggest domain spoofing or registry manipulation. The domain resolves to the IP address 188.114.97.3, hosted by a content delivery network in Canada, which is frequently leveraged to obscure origin infrastructure. The SSL certificate, issued by Google Trust Services (WE1), does not mitigate the threat, as malicious actors routinely exploit trusted certificate authorities. The domain appears on one security blocklist, and its activity was previously blocked by enterprise-grade filtering systems. Current status confirms kra47-at.cc has been taken offline, likely due to detection and mitigation efforts. However, the underlying threat remains elevated due to the domain’s recent registration anomaly and the use of infrastructure commonly associated with credential theft operations. Organizations and users are advised to block the domain and IP at the network perimeter, monitor for related indicators of compromise, and implement multi-factor authentication to mitigate credential exposure. Security teams should review logs for prior connections to 188.114.97.3 or interactions with the domain, particularly those involving login prompts or captcha requests, as these are primary indicators of compromise.
网络安全情报 Registrar context
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
Latest Classified Outcome 2026-08-15 02:43:16 UTC
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of kra47-at.cc · checked Mar 27, 2026
网站配置分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。