gwbt39x[.]space
gwbt39x.space — 内容不可用 (HTTP 502). 品牌冒充:Kraken; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 2/93 (CRDF, Gridinsoft); PhishDestroy score 56/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
gwbt39x.space was registered on 21 February 2026. The domain is associated with a crypto‑scam campaign that claims to represent the Kraken cryptocurrency exchange, as indicated by the “Impersonates: kraken” tag. The site employed an SSL certificate identified as R11, which is typical of low‑quality or self‑signed certificates, and received a Gridinsoft trust score of 0 out of 100, confirming a lack of legitimate reputation. VirusTotal analysis recorded detections from 2 of 93 scanning engines, demonstrating that a minority of security products identified malicious behavior, while the remaining vendors reported no issues.
The domain is presently taken offline and has been listed by the PhishDestroy blocklist and at least one additional security blocklist, reinforcing its classification as hostile infrastructure. Publicly available intelligence does not include the hosting IP, autonomous system number, or country of registration, and no page title or content snapshot has been published. Consequently, the exact delivery mechanism, payload type, and any credential‑harvesting forms remain unknown. The limited detection coverage suggests that the campaign may rely on techniques that evade many scanners, or that the site was quickly seized before broader analysis could be performed.
Defenders should immediately add gwbt39x.space to URL filtering and DNS block policies, enforce strict outbound controls to prevent connections to newly registered domains with low trust scores, and monitor threat‑intel feeds for re‑registration attempts. Given the brand‑impersonation focus, organizations that use Kraken services should alert users to unsolicited communications referencing this domain and advise verification through official Kraken channels. Ongoing collection of hosting data and rapid sharing of any new indicators will improve detection of related infrastructure.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。