sso-krakken-portal[.]framer[.]website
“ikraken | sign in your account *”
sso-krakken-portal.framer.website — المحتوى غير متوفر. انتحال العلامة التجارية: Kraken; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 9/95 (ChainPatrol, alphaMountain.ai, CyRadar, Ermes, Google Safebrowsing); URLQuery 100 det.; Spamhaus DBL_PHISH; PhishDestroy score 95/100. مسجّل النطاق: CSC.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of sso-krakken-portal.framer.website indicates a credential‑ harvesting site that impersonates the Kraken cryptocurrency exchange. The domain was created on 19 November 2021 and is registered through CSC Corporate Domains, Inc. Its authoritative nameservers are ns-1243.awsdns-27.org, ns-1818.awsdns-35.co.uk, ns-336.awsdns-42.com and ns-792.awsdns, confirming that the zone is hosted on Amazon Route 53. The site resolves to IP 52.223.52.2, an address owned by Amazon.com, Inc. (AS16509) located in the United States. TLS is provided by a Let’s Encrypt certificate (issuer E7), and the server advertises HSTS and HTTP/3, typical of modern web platforms.
Technology fingerprints show Framer Sites, React, and standard web security headers. The page title returned by the server is “ikraken | sign in your account *”, matching the known brand‑impersonation pattern for Kraken. VirusTotal scans have flagged the domain by 9 of 95 security vendors, and the domain appears on a single security blocklist. PhishDestroy has already taken the site offline and the current HTTP response is 404, indicating that the malicious landing page is no longer publicly reachable.
Defenders should continue to block the domain at perimeter filters, DNS sinks, and proxy layers, even though the site is currently offline, because the infrastructure (same nameservers, IP range, and certificate) may be reused for future campaigns. Monitoring of the associated AWS IP block and the Let’s Encrypt certificate fingerprint can provide early warning of re‑activation. Additionally, security teams should update threat intelligence feeds with the observed page title and the exact domain string to improve detection of similar Kraken impersonation attempts. No further evidence about the payload or credential collection mechanism is available, so analysts should treat the absence of a live page as a temporary mitigation rather than a permanent resolution.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب