support-kraken-log-learn[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Gespeicherte Beobachtung
Beobachteter Titelkontrast
Zusammenfassung der Beweislage
On 23 July 2026 the domain support-kraken-log-learn.pages.dev was observed as an offline site that had been used for brand impersonation targeting Kraken. The domain was registered on 21 February 2026 through Cloudflare, Inc. and resolves to the IP address 172.66.44.246, which belongs to AS13335 Cloudflare, Inc. in the United States. DNS resolution is served by the Cloudflare nameservers wren.ns.cloudflare.com and eoin.ns.cloudflare.com. HTTPS is provided by a Google Trust Services certificate (WE1), and the site advertised HTTP/3 and HSTS, indicating a modern Cloudflare edge configuration.
The page title returned by the server is “Suspected phishing site | Cloudflare”, and the HTTP response code is 403, consistent with a takedown or block page. Reputation services rate the domain poorly: Scamadviser assigns a trust score of 1 / 100, Gridinsoft 0 / 100, and the site appears on a single security blocklist maintained by PhishDestroy. VirusTotal analysis recorded 12 detections out of 93 scanned vendors, reinforcing the malicious classification. The campaign was labeled as a crypto‑scam and specifically impersonates the Kraken cryptocurrency exchange brand.
The offline status indicates that the hosting provider has removed the content, but the infrastructure – Cloudflare‑proxied IP, certificate, and DNS configuration – remains reusable for future impersonation attempts. Uncertainty remains regarding the exact phishing kit or credential‑harvesting method employed, as no page content has been captured beyond the generic Cloudflare block page. Defensive recommendations include adding the domain and its IP address to internal blocklists, monitoring for new subdomains under the same registrar or nameservers, and employing real‑time URL filtering that references the observed trust scores and VirusTotal detection count. Continuous observation of Cloudflare‑originated IP ranges for rapid redeployment of similar domains is advised.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
Domainstatus
Erreichbar → Nicht erreichbar
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
Technologien
3 Technologien mit hoher Konfidenz erkannt
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of support-kraken-log-learn.pages.dev · checked Apr 13, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt