kreaikeniluogin[.]webflow[.]io
“404 - Page not found”
kreaikeniluogin.webflow.io — Контент недоступний. Зведення доказів: VirusTotal 19/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Ermes); URLQuery 3 alerts; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 95/100. Реєстратор: Webflow.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain kreaikeniluogin.webflow.io has been confirmed as a fake login portal designed for credential harvesting. Analysis indicates the site was operational as a phishing endpoint targeting user authentication credentials, though it currently returns a 404 - Page not found response, suggesting recent takedown or abandonment. No specific brand impersonation has been conclusively identified, but the infrastructure aligns with generic credential theft campaigns. Infrastructure analysis reveals the domain was registered through Webflow and resolves to the IP address 104.18.36.248, hosted on AS13335 Cloudflare, Inc. in the United States. The SSL certificate is issued by Google Trust Services (WE1), a common configuration for phishing sites leveraging legitimate CDN infrastructure. The domain was created on March 04, 2026, though this date may reflect a placeholder or misconfiguration. Security vendors on VirusTotal flagged the domain at a rate of 19/95, indicating moderate to high confidence in malicious classification. The domain appears on one security blocklist and is flagged by Google Safe Browsing as phishing. The page title 404 - Page not found further suggests the site was recently disabled or moved. Current status indicates the domain is offline, though residual risk remains due to potential re-activation or migration to alternative infrastructure. Organizations are advised to block the domain and IP address 104.18.36.248 at the perimeter level. End-users should be alerted to the credential harvesting threat, particularly if login attempts were made during the site's active period. Security teams are recommended to monitor for related domains registered through Webflow or resolving to Cloudflare IPs, as these indicators are frequently reused in phishing campaigns. Credential rotation is advised for any accounts potentially exposed to this infrastructure.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | kreaikeniluogin.webflow.io |
phishing | Phishing Block |
| DNS4EU | kreaikeniluogin.webflow.io |
malicious | Sinkholed |
| Cloudflare DNS | kreaikeniluogin.webflow.io |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога