ktreinkenslogi[.]webflow[.]io
“Kraken® Login® - Log_In to My - Account (official* Website)”
ktreinkenslogi.webflow.io — İçerik kullanılamıyor. Marka kimliğine bürünme: Kraken; Dolandırıcılık türü: Crypto Scam. Kanıt özeti: VirusTotal 14/95 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 92/100. Kayıt kuruluşu: MarkMonitor.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
On July 23, 2026 analysts observed the domain ktreinkenslogi.webflow.io hosting a page titled “Kraken® Login® - Log_In to My - Account (official* Website)”. The page title explicitly references the Kraken brand, indicating a brand‑impersonation attempt. The site resolves to IP 104.18.36.248, which belongs to Cloudflare (AS13335) and is located in the United States. The domain uses Cloudflare’s DNS service (journey.ns.cloudflare.com, lamar.ns.cloudflare.com) and serves content over HTTP/3 with a TLS certificate issued by Google Trust Services under the WE1 hierarchy.
The certificate chain is legitimate, but the presence of a Cloudflare front‑end does not guarantee benign intent. VirusTotal analysis shows that 14 of 95 security scanners flagged the domain, and Google Safe Browsing classifies it as social‑engineering. The domain appears on a single public blocklist and has been added to the PhishDestroy blocklist, confirming its malicious reputation. Registration records list MarkMonitor, Inc. as the registrar, and the domain was created on 08 May 2013, suggesting the infrastructure may be reused for new campaigns.
HTTP requests return a 404 status, indicating the malicious page may no longer be hosted, and the current status is listed as offline. While the technical indicators confirm a high‑risk crypto‑scam targeting Kraken users, the exact payload, credential‑harvesting mechanisms, and phishing kit remain unverified because the page content has not been captured. Defenders should continue to block ktreinkenslogi.webflow.io at DNS and proxy layers, monitor for any resurgence of the domain, and update detection rules to flag the observed page title and the associated Cloudflare IP range. Additional telemetry from endpoint sensors should be collected to identify any attempted credential submission to this domain, and users of Kraken services should be reminded to verify URLs against the official Kraken domain.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Arşivlenmiş Kanıtlar
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin