karakein-login[.]pages[.]dev
“Suspected phishing site | Cloudflare”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
Analysis of karakein-login.pages.dev indicates a high‑risk brand‑impersonation campaign targeting Kraken. The domain was registered on February 21, 2026 through Cloudflare, Inc. and resolves to IP address 172.66.47.203, which belongs to Cloudflare (AS13335) and is located in the United States. DNS resolution uses Cloudflare’s authoritative nameservers tiffany.ns.cloudflare.com and george.ns.cloudflare.com. The site presents a Cloudflare‑generated page titled "Suspected phishing site | Cloudflare" and returns an HTTP 403 status code, suggesting the content has been taken offline.
Despite the offline state, the domain remains listed on at least one security blocklist and is actively blocked by the PhishDestroy service. Google Safe Browsing flags the domain for social engineering, and VirusTotal reports that 12 of 95 scanned security vendors have flagged it as malicious. Additional infrastructure signals include enforced HSTS, support for HTTP/3, and an SSL certificate issued by Google Trust Services under the WE1 label. The Gridinsoft trust score of 0 out of 100 further underscores the lack of legitimacy.
Defenders should treat any traffic to this domain as hostile, block DNS resolution and HTTP requests at network perimeters, and monitor for related indicator hashes or URLs that reference the Kraken brand. Continuous watch of Cloudflare‑hosted IP ranges for similar impersonation patterns is advised, as is updating endpoint protection with the observed vendor detections. Because the site is offline, threat actors may shift to new domains; rapid response to newly observed domains that share the same registrar, nameserver set, or hosting infrastructure will help mitigate re‑deployment of this campaign.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
المخطط الزمني للاكتشاف
التقنيات
حُدّدت ٣ تقنيات عالية الثقة
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب