rabinhood-login[.]gitbook[.]io
“Róbinhood Login | Log in to My Account | Róbinhood Login | Log in to My Account”
rabinhood-login.gitbook.io — Неперевірений. Уособлення бренду: Across; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); PhishDestroy score 95/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain rabinhood-login.gitbook.io is currently active and classified as a high‑risk brand‑impersonation operation. It presents a page title that reads "Róbinhood Login | Log in to My Account | Róbinhood Login | Log in to My Account," indicating an attempt to lure victims into entering credentials for a service that resembles Robinhood. The domain is explicitly identified as a credential‑phishing vector targeting users across the internet.
Infrastructure analysis shows the site is served through Cloudflare, with authoritative nameservers dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com. The host resolves to IP address 172.64.147.209, which belongs to AS13335 (Cloudflare, Inc.) and is geolocated in the United States. TLS termination is provided by Google Trust Services under the WE1 certificate, and the service supports HTTP/3. An HTTP 307 redirect is observed, suggesting the site may forward traffic to additional pages after initial access.
Detection data reinforces the malicious assessment. VirusTotal records indicate that 20 out of 95 security vendors have flagged the domain, and the site appears on two independent phishing blocklists, including PhishDestroy and PhishingDB. Gridinsoft assigns a trust score of 0 out of 100, and the domain is listed on two broader security blocklists. The page title, combined with the high vendor detection rate and blocklist presence, provides concrete evidence of a credential‑phishing campaign.
Defenders should block the domain at network and DNS layers, incorporate it into email filtering rules, and monitor for any outbound connections to the associated IP address. Continuous reconnaissance of the domain’s DNS records is advised, as Cloudflare‑hosted infrastructure can be re‑configured rapidly. Organizations should also educate users about the specific page title pattern to reduce the likelihood of credential submission to this fraudulent site.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога