kraaken[.]idlogin-auth[.]com
“Welcome to nginx!”
kraaken.idlogin-auth.com — error del servidor (HTTP 502). Suplantación de marca: Kraken; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 7/93 (ADMINUSLabs, CRDF, CyRadar, Fortinet, Kaspersky); URLQuery 2 det.; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 75/100. Registrador: NiceNIC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain kraaken.idlogin-auth.com was registered on 27 February 2026 through NiceNIC International Group Co., Limited and is hosted on the IP address 192.241.120.160, which belongs to AS55286 B2 Net Solutions Inc. in the Netherlands. The authoritative name servers are pns71.cloudns.net, pns72.cloudns.com, pns73.cloudns.net and pns74.cloudns.uk. No TLS certificate was observed; HTTP requests return the default nginx welcome page titled “Welcome to nginx!”, indicating a lack of a legitimate login interface. The site is classified as a crypto‑scam that impersonates the Kraken exchange, and it has been flagged by seven of ninety‑three VirusTotal scanners.
It appears on three public blocklists and is actively blocked by PhishDestroy, MetaMask and SEAL. As of the report date (24 July 2026) the host is offline, which limits real‑time analysis of payloads or phishing pages. Evidence suggests the operator leveraged a generic cloud‑hosting provider and a popular DNS service to achieve rapid deployment. Defenders should continue to monitor the IP range associated with AS55286, enforce domain‑based blocking for any sub‑domains of idlogin-auth.com, and update email and web filtering rules to include the full domain string.
Because the site currently returns only an nginx placeholder, any future activation is likely to involve a forged Kraken login page or cryptocurrency withdrawal prompt. Continuous threat‑intel feeds, especially those from the blocklist providers that already listed this domain, should be consulted for updates. Organizations using Kraken services should educate users about unsolicited login requests and verify URLs against the official Kraken domain. The lack of SSL, the recent registration date, and the rapid blocklist inclusion are consistent with a short‑lived impersonation campaign.
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Registration: idlogin-auth.com
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain idlogin-auth.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-16 03:04:43 UTC
Análisis de VirusTotal
Datos y informes externos
PD-20260227-A92489 Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.