# xn--krken12-bn4c.com — SUSPICIOUS > xn--krken12-bn4c.com is a fake login portal flagged by 1/95 security vendors. Check the full report. ## Summary PhishDestroy identifies an active phishing domain mimicking a legitimate login portal at xn--krken12-bn4c.com, designed to steal user credentials. This domain was flagged by only 1 out of 95 security vendors on VirusTotal, indicating low detection despite clear malicious intent. Registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on January 13, 2025, the site resolves to IP 104.21.51.177 and holds a Let's Encrypt SSL certificate, which may lend false legitimacy to unsuspecting users. This domain was created on January 13, 2025, and currently resolves to IP 104.21.51.177. Its SSL certificate, issued by Let's Encrypt, increases the risk of user trust, a common tactic in phishing campaigns. The domain’s low detection rate—only 1 out of 95 security vendors flagged it—suggests it may evade automated defenses, particularly for users relying solely on browser-based warnings. The use of an international registrar further complicates tracking, as such registrars often have lax oversight for malicious domains. If you visited xn--krken12-bn4c.com, immediately cease any input of credentials or personal data. Disconnect from the network and run a full antivirus scan. Change passwords for any accounts that may have been exposed, starting with email and financial services. Monitor accounts for unusual activity and report the domain to your IT security team or the platform being impersonated. Avoid clicking links in emails or messages related to this domain, as they may lead to further phishing attempts. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2025-01-13 14:30:27 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 104.21.51.177 ## Detection Status - VirusTotal: 1 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/f8b61fee-127b-43f9-a4e6-f4c74b8402f0 - PhishDestroy: https://phishdestroy.io/domain/xn--krken12-bn4c.com/ - LLM endpoint: https://phishdestroy.io/domain/xn--krken12-bn4c.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/xn--krken12-bn4c.com/ Last updated: 2026-03-28