klarna-help[.]de
ملخص الأدلة
The domain klarna-help.de has been identified as a credential theft operation specifically targeting users of the Klarna payment service. Analysis confirms the domain is currently offline, though prior activity indicates an active attempt to harvest login credentials, payment details, or personal information under the guise of the legitimate Klarna brand. This assessment is based on infrastructure analysis, vendor detections, and historical threat intelligence associated with the domain. Infrastructure analysis reveals the domain was registered on February 21, 2026, an anomalous future date suggesting potential registrar manipulation or misconfiguration. It resolves to the IP address 172.67.211.74, hosted on AS13335 Cloudflare, Inc., a common obfuscation tactic used to mask malicious infrastructure. The domain is flagged by 14 of 95 security vendors on VirusTotal, with one confirmed appearance on a security blocklist. The SSL certificate, issued under the identifier WE1, lacks transparency and further indicates a low-trust deployment. These indicators collectively point to a deliberately constructed phishing environment designed to exploit Klarna’s brand reputation. Current status confirms the domain has been taken offline, though residual risk remains for users who may have interacted with it during its active phase. Organizations and individuals are advised to review access logs for connections to 172.67.211.74 or klarna-help.de, particularly those originating from payment processing or customer support workflows. Security teams should update blocklists to include the domain and IP, and monitor for any re-registration attempts under similar naming conventions. Users who entered credentials on this domain should immediately reset passwords, enable multi-factor authentication, and review financial statements for unauthorized transactions. Proactive threat hunting for related infrastructure, such as subdomains or linked IPs, is recommended to mitigate potential follow-up attacks.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 10/08/2026
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب