kra47at[.]euro-fitnes[.]ru
“krab1 - платформа CC мониторинга блокчейн-активов”
kra47at.euro-fitnes.ru — 内容不可用. 证据摘要: VirusTotal 1/95 (SOCRadar); PhishDestroy score 63/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain kra47at.euro-fitnes.ru was registered on 21 February 2026 and is currently offline. Historical DNS data shows it resolved to the IPv4 address 193.105.134.30, which is allocated to a network in Sweden (AS42237, operated by w1n ltd). The web server presented an SSL certificate identified as “R12”; no further certificate details are available. The only visible page title retrieved before takedown was “krab1 - платформа CC мониторинга блокчейн-активов”, indicating a reference to a blockchain‑monitoring platform, though the content of the site was not captured for analysis.
VirusTotal scanned the domain and reported a single positive detection out of 95 security vendors, confirming that at least one vendor classified the site as malicious. The domain appears on one public blocklist and is listed as blocked by PhishDestroy, reinforcing the malicious assessment. No additional intelligence such as Safe Browsing, Open Threat Exchange, or registrar reputation is provided.
Given the limited but consistent indicators—recent creation, association with a Swedish host, a non‑standard SSL certificate, a malicious detection count, and inclusion on blocklists—the infrastructure aligns with typical generic phishing operations. Defenders should continue to deny any network traffic to 193.105.134.30, ensure that the domain is added to internal blocklists, and monitor for re‑use of the same IP address or similar sub‑domains under the euro‑fitnes.ru parent zone. Future investigations should focus on capturing the site’s payload, identifying the phishing kit if any, and correlating the observed page title with potential target assets to improve attribution.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。