MALICIOUS — CRITICAL
Verifica phishing e sicurezza per robinhoid-login.gitbook.io
robinhoid-login[.]
The domain robinhoid-login.gitbook.io has an elevated risk level and is specifically flagged for brand impersonation.
- VirusTotal
- 14/91
- Blocklists
- No stored match
- Disponibilità
- Ultimo attivo conosciuto · HTTP 307
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
robinhoid-login.gitbook.io — Ultimo attivo conosciuto (HTTP 307). Simulazione del marchio: Robinhood; Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 14/91 (alphaMountain.ai, BitDefender, ESET, Forcepoint ThreatSeeker, Fortinet); URLQuery 100 det.; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. Registrar: Cloudflare.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
The domain robinhoid-login.gitbook.io has an elevated risk level and is specifically flagged for brand impersonation. The domain impersonates the well-known financial services platform Robinhood, posing a significant threat to users who may mistake it for the legitimate site.
Infrastructure analysis reveals that the domain resolves to the IP address 104.18.40.47, which is located in the United States and is registered to Cloudflare, Inc. (AS13335). The domain was created on March 30, 2014, and is currently offline. The SSL certificate is issued by Google Trust Services / WE1. The domain appears on two security blocklists, PhishDestroy and PhishingDB, and has been flagged by 20 out of 95 security vendors on VirusTotal. These detections indicate a high probability of the domain being used for malicious activities, particularly those aimed at deceiving users into providing sensitive information under the guise of the legitimate Robinhood brand.
To mitigate the risks associated with brand impersonation, users should be vigilant and verify the URL of any Robinhood-related site they visit. Organizations can implement DNS-based blocking and educate their employees about the common tactics used in brand impersonation attacks. Additionally, reporting the domain to the relevant authorities and the affected brand can help in taking further action to prevent such incidents.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisi di VirusTotal
Prove archiviate
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.