kuiukunlicn[.]webflow[.]io
“Crypto Exchange | Bitcoin Exchange | Bitcoin Trading | KuCoin”
Gespeicherte Beobachtung
Beobachteter Titelkontrast
Zusammenfassung der Beweislage
This domain, kuiukunlicn.webflow.io, is identified as a brand impersonation threat targeting KuCoin, a cryptocurrency exchange platform. The page title, 'Crypto Exchange | Bitcoin Exchange | Bitcoin Trading | KuCoin,' directly mimics the legitimate KuCoin interface, suggesting an intent to deceive users into divulging credentials or transferring assets. No explicit crypto drainer kit signatures were detected in initial scans, but the domain’s structure and content align with credential harvesting or fraudulent transaction schemes commonly associated with cryptocurrency phishing operations. Analysis indicates the domain was registered on March 01, 2026, through MarkMonitor, Inc., a registrar frequently leveraged for both legitimate and malicious purposes. It resolves to the IP address 172.64.151.8, hosted on AS13335 (Cloudflare, Inc.), a network often exploited to obfuscate origin infrastructure. VirusTotal detections show 17 out of 95 security vendors flagging the domain as malicious, while it appears on a single third-party blocklist. The SSL certificate, issued by Google Trust Services (WE1), provides a superficial layer of legitimacy but does not mitigate the underlying threat. No Google Safe Browsing (GSB) entries were recorded at the time of analysis, though this may reflect a lag in propagation rather than a clean status. The domain is currently offline, likely due to takedown actions or voluntary suspension by the hosting provider. However, the risk of re-emergence persists, particularly given the use of a reputable registrar and CDN infrastructure. Response actions should include monitoring for domain reactivation, updating blocklists to prevent access, and notifying affected users to reset credentials if exposure is suspected. Organizations are advised to implement strict domain validation policies, particularly for cryptocurrency-related services, and to deploy network-level protections to block known malicious IPs and domains. The elevated risk level remains until the domain’s infrastructure is fully dismantled and no longer poses a threat to users.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | kuiukunlicn.webflow.io |
malicious | Sinkholed |
| OpenDNS | kuiukunlicn.webflow.io |
phishing | Phishing Block |
| DNS4EU | kuiukunlicn.webflow.io |
malicious | Sinkholed |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 12.08.2026
Erkennungszeitleiste
-
VirusTotal
0 → 11
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
VirusTotal
14 → 15
-
VirusTotal
15 → 17
Technologien
3 Technologien mit hoher Konfidenz erkannt
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of kuiukunlicn.webflow.io · checked Mar 1, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt