# giftyfelix.com — MALICIOUS > giftyfelix.com mimics KuCoin to steal credentials. Learn why this offline phishing site is risky and how to stay protected. ## Summary PhishDestroy identifies giftyfelix.com as a medium-risk brand impersonation domain targeting KuCoin, a popular cryptocurrency exchange. The domain was specifically created to deceive users by replicating KuCoin's brand and page titles, increasing the chance of credential theft or other phishing attacks. Evidence supporting this assessment includes the domain's registration via Gname.com Pte. Ltd. and its appearance on one security blocklist. It was flagged by 9 out of 95 VirusTotal security vendors, indicating suspicious or malicious content. The domain resolved to IP 104.21.52.180 before it was taken offline. The fraudulent use of the KuCoin brand and the page title directly referencing KuCoin further confirms its intent to mislead users. Users are advised to avoid engaging with giftyfelix.com or providing any personal information. Since the domain is currently offline, risk exposure is minimized for now. However, vigilance is necessary as similar domains may appear. Always verify URLs carefully, use official exchange websites, and consider enabling multi-factor authentication on your crypto accounts to enhance security. ## Threat Details - Verdict: MALICIOUS - Site status: dead (HTTP 0) - Target brand: KuCoin - Page title: KuCoin ## Domain Intelligence - Registered: 2026-03-05 01:07:02 - Registrar: Gname.com Pte. Ltd. - Country: SG - IP: 104.21.52.180 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: mona.ns.cloudflare.com nikon.ns.cloudflare.com - SSL Issuer: none ## Detection Status - VirusTotal: 9 vendors flagged Vendors: ["alphaMountain.ai", "CRDF", "CyRadar", "Emsisoft", "Fortinet", "Netcraft", "OpenPhish", "Trustwave", "Webroot"] - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["PhishDestroy"] ## Evidence - Screenshot: https://i.ibb.co/whzCPhV3/eac1b6e0f69c.png - Cloudflare Radar: https://radar.cloudflare.com/domains/giftyfelix.com - PhishDestroy: https://phishdestroy.io/domain/giftyfelix.com/ - LLM endpoint: https://phishdestroy.io/domain/giftyfelix.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/giftyfelix.com/ Last updated: 2026-03-19