online[.]kraken19at-t[.]ru
“Онлайн торговля - Kraken Marketplace”
online.kraken19at-t.ru — 内容不可用. 品牌冒充:Kraken; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 9/95 (BitDefender, CRDF, CyRadar, Fortinet, G-Data); Spamhaus DBL_PHISH; PhishDestroy score 77/100. 注册商: REGRU-RU.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of online.kraken19at-t.ru shows a recently registered domain (created 2 December 2025) operated from a Russian IPv6 address 2a00:f940:2:2:1:1:0:172 belonging to ASN 197695, which is registered to REG.RU. The domain is hosted on nameservers ns1.hosting.reg.ru and ns2.hosting.reg.ru, both tied to the same registrar. No TLS certificate is presented, indicating the site does not serve HTTPS traffic. The only visible page title retrieved before takedown reads “Онлайн торговля - Kraken Marketplace”, directly referencing the legitimate Kraken brand.
Intelligence classifies the site as a crypto‑scam that impersonates Kraken, and it appears on a single external blocklist where PhishDestroy has already taken the domain offline. VirusTotal scans report nine detections out of ninety‑five scanners, confirming malicious activity. The lack of SSL, combined with the brand‑impersonating title and the detection footprint, suggests the domain was used to lure victims into fraudulent cryptocurrency transactions.
While the site is currently offline, its infrastructure components remain publicly resolvable and could be re‑activated. Defenders should continue to block the IP address and associated hostnames at network perimeter, add the domain to internal blacklist feeds, and monitor for any re‑registration attempts or similar patterns from the same registrar or name‑server set. Additional scrutiny of traffic targeting the IPv6 block and any future DNS queries for similar Kraken‑related terms is recommended to prevent recurrence.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。