cdnbinance[.]com[.]cn
Phishing and security check for cdnbinance.com.cn
“cdnbinance.com.cn”
This domain, cdnbinance.com.cn, presents a direct threat to users of the Binance cryptocurrency exchange platform by masquerading as an official content delivery network endpoint. The site is engineered to harvest login credentials, two-factor authentication codes, and other sensitive account details through deceptive login portals that replicate Binance’s legitimate interface. Given the high-value nature of cryptocurrency accounts, successful phishing attempts could result in immediate financial theft, unauthorized transactions, and irreversible asset loss. The domain’s infrastructure is designed to exploit user trust in Binance’s branding, leveraging visual and functional mimicry to deceive even security-conscious individuals. Analysis of the domain’s technical indicators confirms its malicious intent. The domain was registered on July 5, 2026, through 福州中旭网络技术有限公司, a registrar frequently associated with phishing and fraudulent domains. VirusTotal detection metrics reveal that 1 of 95 security vendors has flagged cdnbinance.com.cn as malicious, a low but notable detection rate that suggests either evasion techniques or recent deployment. The domain resolves to the IP address 188.114.96.3, which has been observed in prior phishing campaigns targeting financial services. Additionally, the SSL certificate issued by Google Trust Services provides a false sense of security, as users may interpret the presence of HTTPS as legitimacy. AlienVault OTX records further corroborate the threat, with the domain appearing in at least one threat intelligence pulse, indicating its inclusion in active phishing tracking efforts. Users who have visited cdnbinance.com.cn or entered credentials on the site should assume their account has been compromised. Immediate action is required: revoke all active sessions on the legitimate Binance platform, enable two-factor authentication if not already active, and monitor account activity for unauthorized transactions. Change passwords for Binance and any other platforms where the same credentials were reused. If financial losses have occurred, report the incident to local law enforcement and relevant financial authorities. Forensic analysis of the device used to access the phishing site is recommended to check for malware or persistent threats. Organizations should update their email and web filtering rules to block cdnbinance.com.cn and its associated IP address, 188.114.96.3, to prevent further exposure. Vigilance against similar domains, particularly those using slight variations of legitimate brand names, is critical in mitigating future risks.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Technologies · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive