ScamLens analyzed c0f0d375-dffb-45eb-a568-4aa0d741d90b-00-v05qw8dqw965.kirk.replit.dev using 90+ threat intelligence sources and assigned a trust score of 0/100, classifying it as dangerous.
Trust Score: 0/100
Risk Level: Dangerous
This domain already shows strong risk signals. Stop interacting, preserve the page, chat, phone, and payment evidence, and move into response or reporting immediately.
Quick Answer
This domain already shows strong risk signals. Stop interacting, preserve the page, chat, phone, and payment evidence, and move into response or reporting immediately.
Positive Signals
- + Google Safe Browsing: Safe
- + HTTPS encryption supported
Concerns
- - 4 security sources flagged as suspicious
Score Breakdown
Was this assessment accurate?
c0f0d375-dffb-45eb-a568-4aa0d741d90b-00-v05qw8dqw965.kirk.replit.dev is confirmed malicious
Multiple threat-intelligence feeds agree this domain is dangerous. Treat any data you entered as compromised.
- Close the tab immediatelyContinued browsing increases the chance of drive-by downloads, exploit kits, or session hijacking.
- Run a full antivirus / malware scanIf the site loaded scripts, scan your device. Update your OS and browser to the latest version first.
- Change passwords for any account you enteredRotate the password and enable two-factor authentication on the real site. Watch for unauthorised charges over the next 30 days.
- Report the incidentReporting helps blocklists update faster and protects other potential victims.
Trust but verify — open this domain on unrelated security services and compare the verdict.
Threat-intelligence sources
Checked across 27 sources — 4 flagged this domain
Show source breakdown
Threat-intelligence sources
Checked across 27 sources — 4 flagged this domain
- safe_browsing clean
- urlhaus clean
- cloudflare_radar clean
- cert_transparency clean
- alienvault_otx clean
- phishstats clean
- virustotal flagged
- ipqs clean
- abuseipdb clean
- securitytrails clean
- phishdestroy flagged
- threatfox clean
- shodan_internetdb clean
- phishtank clean
- urlscan clean
- rdap clean
- maltiverse flagged
- dns_security flagged
- wanted_domains clean
- darkweb clean
- openphish clean
- scam_blocklist clean
- maltrail clean
- crypto_scam_feed clean
- phishing_army clean
- hagezi_tif clean
- red_flag_domains clean
ScamLens aggregates real-time signals from 90+ commercial and open-source threat-intelligence providers including Google Safe Browsing, VirusTotal, PhishTank, URLhaus, ThreatFox, Cloudflare Radar, OTX, IPQS, GoPlus, Honeypot.is, and more. A flagged signal is evidence; the absence of flags is not proof of safety. Use the signals below alongside community reports to decide.
Advanced Scan
Comprehensive data lookup across premium sources
- Website history verification
- Detailed WHOIS information
- Reverse WHOIS association
- Traffic rank analysis
- Company registration check
AI Deep Investigation
Cross-check the story, claims, and supporting evidence before you decide
- Everything in Advanced Scan
- AI website content analysis
- AI cross-reference verification
- Claim authenticity validation
- Detailed report with evidence
Comprehensive Investigation
Full-spectrum investigation with company deep search & social intelligence
- Everything in Deep Investigation
- AI company background search
- Social media intelligence
- Detailed suspicious point analysis
- Event timeline & entity connections
This analysis is for informational purposes only and does not constitute a legal determination.
Security Sources
Domain Information
- DNSSEC
- Disabled
SSL/TLS Certificate
No data available
Server Information
- IP Address
- 35.247.106.28
- Hosting Provider
- Google LLC
- ASN
- AS396982 Google LLC
- Server Location
- The Dalles, United States
- Organization
- Google Cloud (us-west1)
Related Intelligence
Technical Details (DNS / Headers / Subdomains)
DNS Records
Email Security
SPF Not Configured DMARC Not Configured| Type | Value |
|---|---|
| A | 35.247.106.28 |
| TXT | heritage=external-dns,external-dns/owner=default,external-dns/resource=service/proxy-kirk/dotdevproxy |
HTTP Security Headers
Channels / Subdomains
No data available
Community Reports
Log in to report and share your experience
Report & Take Down This Website
High-Risk Signals
The risk signals are strong enough. Move on evidence preservation, reporting, and victim response now
This result is no longer just a normal verification case. Moving the chat, phone, payment, and official-reporting path in parallel is usually more important than waiting for more data.
Recommended First
Move into the victim action plan
If you already paid, logged in, or installed tools, use the action plan first to prioritize containment and evidence work.
Move into the website-reporting flow
Move the site, payment evidence, chat trail, and contact points into the formal reporting path.
Add the chat, DM, and payment-pressure trail
Keep the Telegram, WhatsApp, social DM, and payment-pressure trail in the same timeline.
Check the callback number and SMS
If the actor also used calls, SMS, or one-time codes, verify that phone path next.
The results are based on multiple third-party data sources and AI models. False positives or negatives may occur. This report should not be used as the sole basis for any decision. Please verify with additional sources.
If a loss already happened, move into the response flow now
Delay is the main risk with high-risk domains. Prioritize freezes, credential resets, reporting, and evidence preservation now.
If no loss happened yet, continue with the website-reporting and official-agency paths next.
Related Security Guides
Learn more about how to protect yourself from this type of threat.
Understanding this threat
FAQ
Is c0f0d375-dffb-45eb-a568-4aa0d741d90b-00-v05qw8dqw965.kirk.replit.dev safe to visit?
c0f0d375-dffb-45eb-a568-4aa0d741d90b-00-v05qw8dqw965.kirk.replit.dev received a trust score of 0/100 from ScamLens, indicating high risk. 4 threat intelligence sources flagged this domain as potentially dangerous. We strongly advise against visiting or sharing personal information.
Was c0f0d375-dffb-45eb-a568-4aa0d741d90b-00-v05qw8dqw965.kirk.replit.dev flagged by any threat databases?
c0f0d375-dffb-45eb-a568-4aa0d741d90b-00-v05qw8dqw965.kirk.replit.dev was flagged by 4 out of 30+ threat intelligence sources. Specifically flagged by: virustotal, phishdestroy, maltiverse, dns_security. The detected threat categories include: general threat.
How old is c0f0d375-dffb-45eb-a568-4aa0d741d90b-00-v05qw8dqw965.kirk.replit.dev?
Registration date information for c0f0d375-dffb-45eb-a568-4aa0d741d90b-00-v05qw8dqw965.kirk.replit.dev is not publicly available through WHOIS records, which can itself be a risk indicator.
Does c0f0d375-dffb-45eb-a568-4aa0d741d90b-00-v05qw8dqw965.kirk.replit.dev use HTTPS and have a valid SSL certificate?
ScamLens could not verify the SSL certificate details for c0f0d375-dffb-45eb-a568-4aa0d741d90b-00-v05qw8dqw965.kirk.replit.dev during this scan. Treat this as unavailable evidence, not as proof that the site is safe or unsafe.
What security headers does c0f0d375-dffb-45eb-a568-4aa0d741d90b-00-v05qw8dqw965.kirk.replit.dev implement?
No security header information was available for c0f0d375-dffb-45eb-a568-4aa0d741d90b-00-v05qw8dqw965.kirk.replit.dev.
What does the ScamLens community think about c0f0d375-dffb-45eb-a568-4aa0d741d90b-00-v05qw8dqw965.kirk.replit.dev?
No community votes or reports have been submitted for c0f0d375-dffb-45eb-a568-4aa0d741d90b-00-v05qw8dqw965.kirk.replit.dev yet. You can be the first to share your experience.
Where is c0f0d375-dffb-45eb-a568-4aa0d741d90b-00-v05qw8dqw965.kirk.replit.dev hosted?
c0f0d375-dffb-45eb-a568-4aa0d741d90b-00-v05qw8dqw965.kirk.replit.dev is hosted by Google LLC in The Dalles, United States (ASN: ASAS396982 Google LLC).
Is this report useful?
Use this report to tell others to stop interacting now and move straight into containment, evidence preservation, and reporting.
Forward to your parents — they deserve to browse safely too.
About this analysis
This report is generated from real-time data across 90+ threat intelligence sources, combined with AI analysis and community feedback.
Learn about our scoring methodology | Last analyzed: June 4, 2026