suportkucon[.]webflow[.]io
“KuCoin ℓoℊin || Exchange Your Cryptocurrency”
ملخص الأدلة
The domain suportkucon.webflow.io was registered on March 6, 2026 through MarkMonitor, Inc. The site presented a page titled “KuCoin ℓoℊin || Exchange Your Cryptocurrency,” indicating a brand‑impersonation campaign aimed at KuCoin users. TLS termination is handled by Cloudflare, as evidenced by the Google Trust Services / WE1 SSL certificate, and the domain resolves to IP address 104.18.36.248, which belongs to ASN 13335 (Cloudflare, Inc.) and is geolocated in the United States. VirusTotal analysis recorded 16 detections out of 94 security vendors, reflecting a consensus that the domain is malicious. It appears on one public blocklist and has been blocked by PhishDestroy.
The HTTP response returned a 404 status code, and the current operational status is offline. The available intelligence points to a crypto‑scam using a Webflow subdomain to host a counterfeit login portal. While the page title confirms the impersonation intent, the full page content, payload, and any downstream infrastructure have not been captured, leaving those aspects uncertain. No additional indicators such as malware hashes or command‑and‑control servers have been disclosed.
Defenders should add the domain and its resolved IP to network blocklists, update email and web gateway filters with the observed page title, and monitor for future registrations that reuse the same registrar or Cloudflare edge IP range. Authentication attempts to KuCoin originating from this IP or containing the identified title pattern should be flagged for further investigation. Ongoing monitoring of VirusTotal and related threat‑intel feeds is recommended to track any evolution of the campaign.
Data Coverage
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | suportkucon.webflow.io |
malicious | Sinkholed |
| OpenDNS | suportkucon.webflow.io |
phishing | Phishing Block |
| DNS4EU | suportkucon.webflow.io |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
VirusTotal
0 ← 8
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب