MALICIOUS — CRITICAL
sso-blockfee[.]webflow[.]io
This domain, sso-blockfee.webflow.io, is actively flagged as a high-risk credential phishing site targeting BlockFi users, as indicated by its page title 'BlockFi login' and confirmed scam classification.
- VirusTotal
- 18/91
- Blocklists
- No stored match
- Kullanılabilirlik
- Bilinen son aktif · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
sso-blockfee.webflow.io — Bilinen son aktif (HTTP 200). Marka kimliğine bürünme: Blockfi; Dolandırıcılık türü: Credential Phishing. Kanıt özeti: VirusTotal 18/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 3 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. Kayıt kuruluşu: Webflow.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
This domain, sso-blockfee.webflow.io, is actively flagged as a high-risk credential phishing site targeting BlockFi users, as indicated by its page title 'BlockFi login' and confirmed scam classification. Registered on April 28, 2026, through Webflow, the domain resolves to IP 172.64.151.8, hosted on Cloudflare infrastructure in Canada. Infrastructure analysis reveals the use of Webflow for hosting, Cloudflare for CDN and security services, and HTTP/3 for connectivity, which may obscure origin details. The domain lacks configured nameservers, a potential red flag for ephemeral or misconfigured phishing infrastructure. SSL certificate issued by Google Trust Services (WE1) provides encryption but does not validate legitimacy, as phishing sites commonly use valid certificates. The domain is currently active, returning an HTTP 200 status, and appears on at least one security blocklist, with 18 of 91 security vendors on VirusTotal flagging it as malicious. Trust scores from Gridinsoft and Scamadviser are both 1/100, further indicating high risk. Defenders should prioritize blocking this domain at DNS, proxy, and endpoint levels, and monitor for credential submission attempts or related C2 callbacks. The exact phishing kit or post-compromise behavior is not yet analyzed, but the domain’s structure and hosting choices align with common credential harvesting tactics.
Veri kapsamı13 recorded checks
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | sso-blockfee.webflow.io |
malicious | Sinkholed |
| DNS4EU | sso-blockfee.webflow.io |
malicious | Sinkholed |
| OpenDNS | sso-blockfee.webflow.io |
phishing | Phishing Block |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 3 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of sso-blockfee.webflow.io · checked Apr 28, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.