MALICIOUS — HIGH
akrn[.]to
Analysis of akrn.to as of July 24, 2026 shows a high‑risk brand‑impersonation campaign targeting Kraken users.
- VirusTotal
- 3/91
- Blocklists
- No stored match
- التوفر
- آخر نشاط معروف · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
akrn.to — آخر نشاط معروف (HTTP 200). انتحال العلامة التجارية: Kraken; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); PhishDestroy score 69/100. مسجّل النطاق: Government of Kingdom ….
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
Analysis of akrn.to as of July 24, 2026 shows a high‑risk brand‑impersonation campaign targeting Kraken users. The site resolves to 104.21.15.96, an address owned by Cloudflare (AS13335) located in the United States. DNS is served by cash.ns.cloudflare.com and kara.ns.cloudflare.com, and the TLS certificate is issued by Google Trust Services under the WE1 intermediate, indicating a valid HTTPS connection. HTTP responses return status code 200 and the page title reported by scanners is “Академия KRAKEN”, confirming the presence of the Kraken brand in the content. Technical fingerprints include a Node.js stack with React, Next.js, Express, Webpack and HTTP/3, as well as the Yandex.Metrika analytics tag, all typical of modern web applications but not indicative of benign intent.
The domain was registered on April 07, 2025 through the Government of the Kingdom of Tonga, a registrar frequently abused for malicious domains. Reputation checks show a Gridinsoft trust score of 0 out of 100 and the domain appears on a single security blocklist. One of ninety‑five VirusTotal scanners flags the site, and PhishDestroy lists it as blocked, reinforcing the malicious classification. No additional public threat‑intel feeds are referenced in the available data. Defenders should treat any traffic to akrn.to as hostile.
Immediate actions include adding the domain and its resolving IP 104.21.15.96 to deny‑list rules on perimeter firewalls and proxy devices, monitoring DNS logs for lookups, and ensuring endpoint protection solutions are updated to reflect the single vendor detection. Because the site hosts a crypto‑scam façade, users should be warned not to enter credentials or financial information. Continuous monitoring of Cloudflare‑hosted IP ranges for new domains registered by the same registrar may help detect future iterations. The evidence currently lacks visual page analysis, so further sandbox inspection is advised to confirm any credential‑capture mechanisms.
نطاق تغطية البيانات12 recorded checks
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 8 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
JavaScript library for building user interfaces with component-based architecture.
React framework for production with hybrid static and server rendering.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comModule bundler for modern JavaScript applications.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
الأدلة المؤرشفة
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of akrn.to · checked Mar 2, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.