krrkenloggi[.]webflow[.]io
“Kraken Login”
Observation enregistrée
Contraste de titres observé
Résumé des preuves
The domain krrkenloggi.webflow.io has been identified as a brand impersonation threat targeting the cryptocurrency exchange Kraken. Analysis indicates the site functions as a fake login portal, designed to harvest user credentials under the guise of the legitimate Kraken platform. At the time of assessment, the domain is reported as offline, though prior activity remains a concern for historical exposure. Technical indicators reveal the domain was flagged by 13 of 95 security vendors on VirusTotal, a notable detection rate for credential-theft infrastructure. Registration details show the domain was created on May 8, 2013, though the subdomain under webflow.io appears to have been repurposed for malicious activity. The domain resolves to the IP address 172.64.151.8 and is associated with a single security blocklist entry. The SSL certificate is issued by Google Trust Services (WE1), a common characteristic of both legitimate and malicious sites leveraging free certificate authorities. Infrastructure analysis further confirms the domain was registered through MarkMonitor, Inc., a registrar frequently used for both corporate and fraudulent domains. Current status indicates the domain has been taken offline, reducing immediate risk to end users. However, the historical presence of this fake login portal warrants caution. Users who may have interacted with the site should immediately revoke any active sessions, reset credentials for associated accounts, and enable multi-factor authentication where available. Organizations monitoring for brand abuse should update detection rules to include this domain and its associated IP address in historical logs. Continuous monitoring of newly registered subdomains under webflow.io and similar hosting platforms is recommended to identify potential resurgence or copycat campaigns.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
État du domaine
Accessible → Inaccessible
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Technologies
2 technologies identifiées avec une forte confiance
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif