# PhishDestroy threat dossier โ€” kwocoinlogn.webflow.io ================================================================ Fetched: 2026-06-23 17:11:03 UTC Canonical: https://phishdestroy.io/domain/kwocoinlogn.webflow.io/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring โ€” see methodology below) Scam classification: Impersonation Targeted brand: KuCoin ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 13/91 security vendors flagged this domain Flagging vendors: BitDefender, CyRadar, Emsisoft, Fortinet, G-Data, Gridinsoft, Kaspersky, LevelBlue, Lionic, Netcraft, OpenPhish, Sophos, Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.18.36.248 (US, San Francisco) Hosting org: AS13335 Cloudflare, Inc. Registrar: MarkMonitor, Inc. Nameservers: journey.ns.cloudflare.com, lamar.ns.cloudflare.com Registered: 2013-05-08 Expires: 2028-05-08 Page title: ๊„uCoinยฎ%^L๐—ผ๐—ดi๐’ ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-08-25 Status: INVALID chain Fingerprint: 0dc0be3d837e60b4433d84c67385bdc354bb83307d80c71fb67d87f1beec53c6 Subject Alternative Names (related infrastructure โ€” often same operator): - webflow.io ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED โ€” no report required. This domain was neutralised before the abuse-report cycle could be dispatched โ€” either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2013-05-08 (per WHOIS / CT โ€” may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-21 14:13:38 UTC (by PhishDestroy tracker) Last verified: 2026-06-23 16:20:36 UTC Neutralised: 2026-06-22 00:02:27 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019eea18-8fd0-7799-9f96-2b819370e0d2/ Wayback Machine: https://web.archive.org/web/*/kwocoinlogn.webflow.io crt.sh CT logs: https://crt.sh/?q=%25.kwocoinlogn.webflow.io Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=kwocoinlogn.webflow.io AlienVault OTX: https://otx.alienvault.com/indicator/domain/kwocoinlogn.webflow.io URLhaus: https://urlhaus.abuse.ch/host/kwocoinlogn.webflow.io/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-22 23:00:39 UTC โ€” narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] The phishing domain kwocoinlogn.webflow.io impersonates the cryptocurrency exchange KuCoin, using a deceptive page title to lure users into providing their login credentials. Despite being offline, it has been flagged by 13 out of 91 vendors on VirusTotal, indicating its malicious nature. The domain has also been added to public blocklists, including PhishDestroy's, highlighting its threat level. This domain was registered with MarkMonitor, Inc., a registrar known for managing high-profile domains, which may have been an attempt to lend legitimacy to the operation. Hosted on an IP address associated with Cloudflare, Inc., the site used SSL certificates issued by Google Trust Services, possibly to further deceive users into believing the site was secure. The domain's creation date in 2013 suggests it may have been dormant for years before being repurposed for this phishing scheme. PhishDestroy first detected the threat on June 21, 2026, and assigned it a platform risk score of 78 out of 100, indicating a high level of potential harm. The swift action taken to take down the site reflects the ongoing efforts to combat phishing threats. The 13 detections on VirusTotal underscore the domain's malicious intent, while its presence on blocklists serves as a warning to potential victims. This case exemplifies the importance of early detection and swift response in mitigating the risks posed by phishing domains. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 1f894f487d068a2ced95d5cd4f88598c TLS cert SHA-256: 0dc0be3d837e60b4433d84c67385bdc354bb83307d80c71fb67d87f1beec53c6 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe โ€” new scam domains routinely show 0/95 VT for their first 7โ€“30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/kwocoinlogn.webflow.io/ JSON API: https://api.destroy.tools/v1/check?domain=kwocoinlogn.webflow.io Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 168,497 domains (12,458 alive under monitoring, 155,721 confirmed takedowns/dead). Site: https://phishdestroy.io