kocuinloginu[.]webflow[.]io
“KuCoin Login Guide | Step-by-Step Access to Your Exchange”
Gespeicherte Beobachtung
Beobachteter Titelkontrast
This domain, kocuinloginu.webflow.io, poses a direct threat to users of the KuCoin cryptocurrency exchange by impersonating its official login interface. The site presents itself as a "KuCoin Login Guide | Step-by-Step Access to Your Exchange," designed to deceive users into entering their credentials. Once submitted, these credentials are harvested by threat actors, enabling unauthorized access to victims' exchange accounts, potential theft of funds, and further exploitation such as phishing campaigns or crypto draining attacks. The use of a seemingly legitimate guide format increases the likelihood of successful deception, particularly among users unfamiliar with secure authentication practices. Analysis indicates this domain was created on March 06, 2026, and is registered through MarkMonitor, Inc., a registrar commonly used for both legitimate and malicious domains. The domain is flagged by 19 out of 95 security vendors on VirusTotal, a clear indicator of its malicious nature. Additionally, it appears on one security blocklist, further confirming its classification as a threat. Infrastructure analysis reveals the domain resolves to the IP address 172.64.151.8, hosted on Cloudflare's network (AS13335), which is frequently leveraged by threat actors to obfuscate their operations and evade detection. The SSL certificate, issued by Google Trust Services (WE1), adds a layer of apparent legitimacy, though it does not mitigate the underlying malicious intent. Users who have visited kocuinloginu.webflow.io or entered credentials on this site should take immediate action to mitigate potential risks. First, revoke access to any active sessions on the legitimate KuCoin platform and change the account password using a secure, unrelated device. Enable multi-factor authentication (MFA) if not already active, and monitor the account for unauthorized transactions or suspicious activity. If funds have been transferred without authorization, report the incident to KuCoin support and relevant law enforcement or cybercrime reporting agencies. Additionally, scan the device used to access the site for malware, as credential harvesters often deploy secondary payloads. Finally, review connected applications or API keys linked to the account and revoke any that are unrecognized or unnecessary.
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | kocuinloginu.webflow.io |
malicious | Sinkholed |
| DNS4EU | kocuinloginu.webflow.io |
malicious | Sinkholed |
| OpenDNS | kocuinloginu.webflow.io |
phishing | Phishing Block |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 Quellen · synchronisiert am 10.08.2026
Erkennungszeitleiste
-
VirusTotal
stage4.timeline.transition
-
Cloudflare Radar
stage4.timeline.scan_saved · stage4.timeline.open_scan
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt