Security Review

Is kra5.ru legit or a scam?

Our verdict:Dangerous· 25/100

A malicious clone site masquerading as an electronics store while serving as a gateway for illicit Russian-language marketplaces.

kra5.ruScanned 2h ago
0
Trust score
DANGEROUS
Heuristics 76·MT 12
Category tags
phishingfake shop#phishing#fake shop#clone site95% MT confidence

These checks passed — but they don't clear the site. A clean antivirus result, valid SSL, and a calm server only mean it isn't hosting malware; they say nothing about whether the business is real. This verdict is based on the site's conduct and content, not a malware detection.

View density

Analysis Summary

Threat Intelligence
0/92
All engines report clean
Domain Age
Registration date unknown
MT Intelligence
Dangerous
Critical likelihood · 95% confidence
DANGEROUS

Brand impersonation — not the real site

A malicious clone site masquerading as an electronics store while serving as a gateway for illicit Russian-language marketplaces. This page is styled as a brand but is not the brand's real site. Go to the official site directly, and treat any download, login, or payment request here as unsafe.

Website Preview

Screenshot of kra5.ru
LIVE RENDER
kra5.ru

Automated page render — captured in a safe sandbox. What an ordinary visitor would see when loading the site.

MT Intelligence

Advanced threat intelligence
MT Security Analyst
Critical scam likelihoodengineMT · Guardiantrust12/100
MT AgentLive web researchVisual inspectionNetwork correlation
0%
Confidence
The domain kra5.ru is a direct clone of slon4.at, a site already flagged by our threat intelligence for phishing and scam activity. While it presents as a legitimate shop for headphones and power banks, it lacks any verifiable business registration or physical address. Our research confirms that this specific branding is frequently used as a mirror for the 'Kraken' illicit marketplace. The site claims to have processed 47,000 orders over five years, yet the domain itself is a recent registration with no independent customer history. This combination of fake business credentials and darknet ties indicates a high risk of data theft or financial fraud.
Full dossier
Analysis complete

Page Content

The site uses the branding and metadata of 'slon4.at', offering portable electronics like TWS headphones and power banks. It features fabricated statistics, such as a 99% positive review rate and 47,000 completed orders, to create a false sense of authority.

Infrastructure

The domain is hosted behind a common content delivery network and uses a Google-issued SSL certificate. It loads external resources from several suspicious domains, including krab6v.cc and slon4.at, which is typical for mirror sites designed to bypass regional blocks.

Domain History

WHOIS data is obscured, and the domain appears to be a recently repurposed or 'freed' .ru domain. There is no historical record of this domain operating as a legitimate retail business prior to its current state as a clone.

Web Reputation

Our security partners have explicitly blacklisted the 'slon4' brand for phishing. Multiple security outlets report that this network of sites mimics legitimate storefronts to deceive users into surrendering sensitive information or accessing illicit platforms.
Risk Factors
6
  • Confirmed clone of slon4.at, a known phishing and scam brand.
  • Linked to illicit Russian-language darknet marketplace entry points.
  • No verifiable business registration, OGRN, or legal entity details provided.
  • Fabricated business history and order statistics (47k+ orders on a new domain).
  • Multiple security engines and blocklists flag the associated brand as malicious.
  • Missing contact email and physical address despite claiming to be a major retailer.
Positive Signals
1
  • Valid SSL certificate is present.
AI Recommendation
Avoid this site entirely. Do not provide credit card details, phone numbers, or login credentials, as they will likely be stolen or used for illicit purposes.
Next-gen fraud intelligence
Evidence-backedCross-checked

Web Research Findings

Our live research agent queries scam-report databases, consumer-review sites, news coverage, and general web search for kra5.ru, then cross-checks business-registration records and look-alike domain patterns. Everything below is pulled from what it actually found.

Business registration
No public record found
Could not match the site to a registered company — common for small sites.
Clone check
Clones slon4.at
The page impersonates a well-known brand's site.
Typosquat check
No look-alike match
The domain doesn't resemble any well-known brand's spelling.
Web mentions
2 scam reports
Key findings
7 headline facts from open-web research
  • kra5.ru serves the exact page content of slon4.at, an online store claiming to sell portable electronics (wireless headphones, power banks, GaN chargers, portable speakers) with same-day courier delivery in Moscow and SDEK/Boxberry across R
  • The site claims 5 years in operation, 47K+ orders, 99% positive reviews, 12-month warranty, and payments including online card, SBP, SberPay, and cash-on-delivery.
  • No verifiable business registration, physical address, or legal entity details are provided on the page.
  • slon4.at (and variants like slon4.cc) is heavily associated with mirrors and entry points for the Russian darknet marketplace 'Kraken' (Кракен), often promoted in forums as official links for a drug/illicit goods platform.
  • Security tools (Gridinsoft) classify slon4.at-related sites as scam/phishing; multiple clone/phishing domains (e.g. slon4cc.top, slon4--atttt.ru) actively mimic it.
  • Domain appears recently registered or repurposed (listed among freed .ru domains in 2025); no independent customer reviews, Trustpilot, or ScamAdviser data found specifically for kra5.ru.
  • The combination of fake storefront branding, darknet marketplace ties, and lack of transparency matches common Russian-language scam patterns for illicit market mirrors that may steal payment data or deliver nothing.
Scam reports (2)
Direct quotes from public scam databases, forums, and news.
  • Gridinsoftopen

    "Gridinsoft blocks this website because it was classified as scam website. slon4.at should not be treated as a safe website."

  • PhishDestroyopen

    "ALERT: slon4cc.top mimics slon4.at in active phishing scam. This domain operates under the guise of slon4.at , a known legitimate domain, to deceive visitors into surrendering sensitive information or installing malware."

Impersonation / typosquat
Clone of slon4.at

The domain kra5.ru loads content with title and description explicitly branded as 'slon4.at — интернет-магазин портативной электроники с доставкой'. It presents itself as the store while using a completely different domain, a common tactic for mirrors or phishing clones in Russian darknet/underground marketplaces.

Research summary
Narrative write-up from our AI analyst, grounded on the facts above
Our research found that security outlets like Gridinsoft and PhishDestroy have blacklisted the 'slon4' brand for phishing and scam activity. These reports indicate that the site mimics legitimate domains to deceive visitors. Additionally, the branding is widely associated with mirrors for the Kraken illicit marketplace in Russian-language forums, confirming it is not a standard retail operation.

Scam Network Intelligence

Cross-site correlation

This site shares signals with a broader cluster

Moderate correlation

Many scams don't operate alone. We correlate third-party scripts, hosting infrastructure, brand-impersonation signals, and the AI evidence package to detect when a site is part of a broader scam network.

Suspicion score
0/100
ClearLowModerateHighCritical
Evidence (1)
  • Evidence confirms this site is a clone of slon4.at.
Linked signals (1)
Clone of slon4.at

Antivirus Engines

Clean pass · verified
Clean across 92 engines

We cross-check every URL against our antivirus network of 92 malware and blacklist engines. None of them flagged this URL in the last scan.

0Malicious0Suspicious58Harmless92Engines
Clean
Kaspersky
Clean
Bitdefender
Clean
Microsoft
Not in pass
ESET-NOD32
Not in pass
Avira
Not in pass
Sophos
Clean
Fortinet
Clean
Google Safebrowsing
Clean
Emsisoft
Clean

No engine detections. The URL passed every antivirus and blacklist engine we queried in this scan. Stay vigilant — AV coverage is only one signal among many.

Security Scans

Blacklist Check
Not flagged on major threat lists

Checked against the major public blocklists used by browsers and security tools — no hits.

Contact Verification

We fetched the page and looked for real-world contact details. Legitimate businesses almost always publish an email on their own domain, a phone number, and a postal address. Scam shops usually don't.

What We Found
No clear contact details on the page
Emails on site's domainNone
Phone numbers+7 (495) 127-98-34
Postal addressNot listed
Linked social profiles0
Signal Summary
Several contact red flags
  • No contact email found anywhere on the page.
  • No postal address visible on the page.
  • Phone number listed (+7 (495) 127-98-34).

Domain & Encryption

Encryption Certificate
StatusValid
ProtocolTLSv1.3
IssuerGoogle Trust Services · WE1
ExpiresSep 8, 2026 (77d)
Self-signedNo
Hosting & Technology
HostingCloudflare, Inc.
Server locationUS
Web servercloudflare

Redirect Chain

Hops
1
Cross-domain
No
Lookalike
No
Punycode
No
  • 1301http://kra5.ru/
  • 2200https://kra5.ru/

Server Reputation

Abuse Intelligence
Confidence score0%
Reports on file0
ISPCloudflare, Inc.
Usage typeContent Delivery Network

Scam-Type Likelihood

1 scam-type patterns detected
Scam-Type Likelihood

1 of 13 categories showed signals

We check every URL against 13 distinct scam categories so the verdict tells you not just how risky the page is, but what kind of risk it carries. Each meter pulls from page signals, web reports, our AI analyst, vision, and the scam-network cluster — not from raw AV labels.

Top match: Brand Impersonation
Brand Impersonation
Moderate likelihood
30/100
  • AI analyst tagged this as a brand / clone-site impersonation.
  • Clustered with known brand-impersonation infrastructure.

Brand impersonation detected

This page is styled as a known brand but is not the brand's real site.

  • Do not interact with kra5.ru

    Do not enter credentials, deposit money, download files, or install browser extensions from this site.

  • Go to the brand's real site directly

    Type the brand name into a search engine or open it from your bookmarks — don't use links from emails, SMS, ads, or social posts, which are the delivery vectors for impersonation.

  • Never download or sign in here

    Even if the page "just" offers a download or a giveaway, impersonation pages frequently deliver malware or set up follow-up phishing. Assume anything accepted from this site is hostile.

  • Report the impersonation to the brand

    Most major brands have a dedicated abuse or anti-phishing reporting channel — reporting helps them take the site down and protects other users.

    Open

Reputation Sources

How this domain rates across independent threat-intelligence and blocklist providers.

Google Safe Browsing
Not listedCheck ↗
VirusTotal
Not listedCheck ↗
AbuseIPDB
Not listedCheck ↗

Referenced Domains

Outbound domains this page links to or loads resources from. Each links to its own security scan.

Safety FAQ

Common questions about this site, answered directly from the scan data above — so the answers always reflect the latest verdict on this page.

  • Our automated security review flags kra5.ru as dangerous. Multiple threat indicators were detected — treat the site as a scam until proven otherwise.
  • No — kra5.ru scored 25/100 on our trust scale. We detected active threat indicators, so we recommend avoiding the site entirely.
  • Yes. kra5.ru presents a valid TLSv1.3 certificate issued by Google Trust Services · WE1, expiring in 77 days. Note that SSL only encrypts the connection — it does not guarantee that the site itself is trustworthy.
  • No. All 92 antivirus engines in our malware network report kra5.ru as clean.
  • No. kra5.ru is not currently listed on the major browser blocklist feeds that modern browsers use.
  • kra5.ru resolves to an IP operated by Cloudflare, Inc. in US (usage type: Content Delivery Network). Hosting location alone doesn't make a site good or bad, but unusual geography for a brand's claimed country is one of many signals we weigh.
  • This is a permanent record of the scan run on June 22, 2026. The verdict and evidence above reflect that scan and do not change on their own. If circumstances around kra5.ru have changed, MalwareTips staff can run a fresh scan, which re-runs every check from scratch and publishes an updated report.

Final Verdict

0
Trust / 100
Final Verdict·kra5.ru
DANGEROUS

This site is a deceptive clone of the 'slon4.at' electronics store and is linked to illicit marketplace entry points. It uses a fake storefront to harvest data or facilitate transactions for a known darknet network. Do not enter any payment or personal information.

Avoid this site entirely. Do not provide credit card details, phone numbers, or login credentials, as they will likely be stolen or used for illicit purposes.

AV engines
92
MT passes
2
Net signals
1
Scan another URL
Security review completemalwaretips.com/url-scan
Recently scanned

Other Dangerous reports

Browse all reports
Community review

User reviews & comments(0)

Share your experience — "Lost $200 on a fake checkout" is more useful than "Scam". Your review helps others avoid traps.

Loading…
Loading comments…
This report is generated automatically by combining threat intelligence, domain signals, and an AI security analyst. It is informational, not legal advice. Always use your own judgement before sharing personal information or money online.