krknm[.]cc
“KRAKEN - DARKNET MARKET ONION TOR”
证据摘要
The domain krknm.cc was observed resolving to the Cloudflare‑hosted address 172.67.163.137 (AS13335, United States). Registration data indicate the domain was created on 9 December 2025 and is managed by the nameservers amos.ns.cloudflare.com and kinsley.ns.cloudflare.com. The registrar listed is PDR Ltd. d/b/a PublicDomainRegistry.com. No TLS certificate was presented for the site, and the current HTTP status is reported as offline, suggesting the malicious payload may have been taken down or is temporarily inaccessible.
Google Safe Browsing classifies the URL as a social engineering threat, and VirusTotal records 16 of 95 scanned security vendors flagging the domain as malicious. The site appears on a single public blocklist and has been incorporated into one AlienVault OTX pulse, indicating limited but confirmed detection in the threat‑intelligence community. PhishDestroy has also listed the domain as blocked.
The page title returned by the server, “KRAKEN – DARKNET MARKET ONION TOR”, combined with the declared brand target of Kraken, points to a crypto‑related impersonation campaign. The threat type is recorded as a crypto scam, suggesting the operator may have attempted to lure victims into providing cryptocurrency credentials or payments. The lack of an SSL certificate reduces the credibility of any purported secure service and aligns with typical phishing infrastructure that relies on HTTP.
Defenders should add krknm.cc and its resolving IP 172.67.163.137 to firewall and DNS filtering rules, and monitor for any re‑registration or new sub‑domains under the same registrar. Continuous observation of Cloudflare‑served IP ranges for similar brand‑impersonation patterns is recommended. Because the site is presently offline, active takedown verification is limited; however, the existing detection signals justify maintaining the domain on blocklists and alerting users of potential Kraken brand abuse.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月10日
检测时间线
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控