robinhoxblogin[.]gitbook[.]io
“Róbinhood @ Login”
Зведення доказів
This domain is flagged for elevated-risk brand impersonation targeting Robinhood, a financial services platform. Analysis indicates the site is designed to harvest user credentials through a fraudulent login portal, leveraging the brand’s visual identity and domain structure to deceive victims. The threat type is classified as credential theft via brand impersonation, with no evidence of crypto drainer functionality at this time. Infrastructure analysis reveals the domain robinhoxblogin.gitbook.io is hosted on Cloudflare’s content delivery network, resolving to the IP address 104.18.40.47 (AS13335, United States). The domain was registered through Cloudflare, Inc., with a creation date of February 21, 2026, suggesting a recently established operation. Detection metrics include 17 out of 95 security vendors flagging the domain on VirusTotal, while one blocklist (PhishDestroy) has already classified it as malicious. The SSL certificate is issued by Google Trust Services under the identifier WE1, a common configuration for legitimate and malicious domains alike. Mitigation steps for this threat type include immediate reporting to the impersonated brand’s security team for takedown coordination, as well as dissemination of indicators of compromise (IOCs) to enterprise security teams. End users should be advised to verify domain authenticity by cross-referencing official communication channels and avoiding login prompts from untrusted sources. Network-level protections, such as DNS filtering or web gateway rules, should be implemented to block access to the domain and its associated IP. Given the use of Cloudflare infrastructure, additional scrutiny of domains with similar patterns is recommended to identify potential copycat campaigns.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
Статус домену
Доступний → Недоступний
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
Статус домену
Доступний → Недоступний
-
Статус домену
Доступний → Недоступний
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of robinhoxblogin.gitbook.io · checked Mar 2, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога