kraken[.]krab2---cc[.]ru
“Кракен krab2 - безопасная AT авторизация для покупателей”
kraken.krab2---cc.ru — 内容不可用. 品牌冒充:Kraken; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 13/93 (ChainPatrol, BitDefender, Certego, CRDF, CyRadar); PhishDestroy score 89/100. 注册商: REGRU-RU.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain kraken.krab2---cc.ru was registered on December 20, 2025 through the REGRU-RU registrar and resolves to the IPv4 address 91.236.116.210, an AS42237 host located in Sweden and operated by w1n ltd. The authoritative name servers for the zone are ns1.armadns.com and ns2.armadns.com. No TLS certificate was presented for the site, indicating that connections were unsecured. A scan on VirusTotal recorded 13 detections out of 93 security engines, and the domain appears on a single external blocklist.
Gridinsoft assigned a trust score of 0 out of 100, and the site was actively blocked by the PhishDestroy service. The page title retrieved during analysis reads "Кракен krab2 - безопасная AT авторизация для покупателей," which references the Kraken brand and describes a “secure AT authorization for buyers.” The campaign is classified as a crypto‑related scam that impersonates Kraken, consistent with the brand‑impersonation threat type and the elevated risk rating. As of the report date, July 23, 2026, the site is offline, preventing immediate interaction, but the infrastructure details remain valid for threat‑intel correlation.
Defensive teams should update network and endpoint filters to block connections to 91.236.116.210 and any subdomains of kraken.krab2---cc.ru, enforce DNS‑based allow‑list policies that exclude the known name servers, and monitor for future activity using the registrar and ASN indicators. Because the visual content of the landing page has not been captured, analysts should treat any unverified claims about page layout or credential capture mechanisms as uncertain until a live sample is observed. Continuous monitoring of VirusTotal, phishing‑filter feeds, and public reputation services is advised to detect any re‑hosting attempts that reuse the same domain name or hosting infrastructure.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。