kucoin-lxgen[.]gitbook[.]io
“kucoin @ Login”
اكتشاف محفوظ
تنبيه إخفاء المحتوى
- نوع الإخفاء
content_divergence- درجة الإخفاء
- 1/6
ملخص الأدلة
This domain is flagged as an elevated-risk brand impersonation threat targeting KuCoin, a cryptocurrency exchange platform. Analysis indicates the site operates as a credential harvesting portal, presenting a login interface under the title 'kucoin @ Login' to deceive users into submitting sensitive authentication details. The infrastructure and content are designed to mimic legitimate KuCoin services, increasing the likelihood of successful compromise for unsuspecting victims. Infrastructure analysis reveals the domain kucoin-lxgen.gitbook.io was registered through Cloudflare, Inc. and resolves to the IP address 104.18.40.47, located in Canada under Cloudflare’s network. The domain was originally created on March 30, 2014, though the current malicious activity suggests recent repurposing. Security vendor detection on VirusTotal stands at 18 out of 95 engines, indicating moderate but notable consensus regarding its malicious nature. The domain appears on one security blocklist, and its SSL certificate is issued by Google Trust Services (WE1), a common provider for both legitimate and malicious sites. The page title explicitly references KuCoin, reinforcing the brand impersonation tactic. Mitigation against this threat involves immediate domain blacklisting at the network and endpoint levels, particularly for entities handling cryptocurrency transactions. Organizations should update detection rules to flag domains hosted on 104.18.40.47 or associated with Cloudflare registrations exhibiting brand impersonation patterns. User education should emphasize verifying domain authenticity before entering credentials, especially for financial or cryptocurrency platforms. Monitoring for similar domains registered under GitBook or Cloudflare infrastructure may help preempt future campaigns leveraging the same tactics.
Data Coverage
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | kucoin-lxgen.gitbook.io |
malicious | Sinkholed |
| Cloudflare DNS | kucoin-lxgen.gitbook.io |
malicious | Sinkholed |
| DNS4EU | kucoin-lxgen.gitbook.io |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
التقنيات
حُدّدت ٦ تقنيات عالية الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of kucoin-lxgen.gitbook.io · checked Apr 29, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب