MALICIOUS — CRITICAL
crknlogcn[.]gitbook[.]io
This domain, crknlogcn.gitbook.io, has been identified as a credential harvesting phishing site targeting users through deceptive login portals.
- VirusTotal
- 18/95
- Blocklists
- No stored match
- Доступность
- Последний известный активный · HTTP 307
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
crknlogcn.gitbook.io — Последний известный активный (HTTP 307). Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 18/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CRDF); Google Safe Browsing flagged; PhishDestroy score 100/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
This domain, crknlogcn.gitbook.io, has been identified as a credential harvesting phishing site targeting users through deceptive login portals. As of the latest verification, the domain is offline, though it previously exhibited active malicious behavior. No specific brand impersonation has been confirmed, but the infrastructure aligns with common phishing tactics designed to harvest sensitive authentication details. Analysis indicates the domain was flagged by 18 of 95 security vendors on a leading malware detection platform, signaling broad consensus on its malicious nature. Registered through a privacy-focused provider on March 30, 2014, the domain resolved to the IP address 198.18.0.189, hosted on a content delivery network operated by a large US-based infrastructure provider. The SSL certificate was issued by a trusted public certificate authority, which is frequently exploited by threat actors to lend legitimacy to phishing pages. The domain appeared on one security blocklist and was explicitly flagged for phishing by a major web safety service. Infrastructure analysis reveals the domain leveraged a widely used documentation hosting platform, which is often abused due to its free tier and ease of deployment. While currently offline, the domain’s historical activity and detection metrics warrant continued monitoring. Organizations are advised to block the domain at the DNS and proxy levels, revoke any cached SSL certificates associated with it, and conduct internal audits for potential exposure. Users who may have interacted with the domain should reset credentials immediately and enable multi-factor authentication on all critical accounts.
Охват данных13 recorded checks
Сигналы безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.