kra50r[.]ru
“404 Not Found”
kra50r.ru — 内容不可用. 证据摘要: VirusTotal 7/93 (alphaMountain.ai, Chong Lua Dao, CRDF, CyRadar, Forcepoint ThreatSeeker); PhishDestroy score 71/100. 注册商: RU-CENTER-RU.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, kra50r.ru, is flagged as a credential theft phishing operation targeting users through deceptive login portals. Analysis indicates no direct brand impersonation or cryptocurrency drainer kit association, but the infrastructure aligns with credential harvesting campaigns. The domain was designed to mimic legitimate authentication pages, likely capturing usernames, passwords, and session tokens for unauthorized access to accounts or further exploitation. Infrastructure analysis reveals the domain was registered on November 19, 2025, through RU-CENTER-RU, a registrar frequently associated with malicious activity. It resolved to the IP address 188.114.97.3 and was detected by 7 out of 95 security vendors on VirusTotal. The domain appears on one security blocklist and holds a Gridinsoft trust score of 0/100, indicating high confidence in its malicious nature. The page title consistently returned a 404 Not Found error, suggesting either takedown efforts or deliberate evasion of automated analysis tools. Currently, kra50r.ru is offline, likely due to hosting provider intervention or domain suspension. However, the infrastructure may resurface under a different domain or IP address. Response actions include monitoring for related domains registered through the same registrar or resolving to the same IP. Organizations should block the domain and IP at the perimeter, update endpoint detection rules, and conduct retrospective log analysis to identify any prior interactions with this infrastructure. Remaining risk includes potential reuse of the same registrar or hosting provider for future phishing campaigns.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。