kcn[.]co[.]com
“AF88 Kcn - Trang Chủ Chính Thức AF88.COM - Nhà Cái Uy Tín”
Observation enregistrée
Contraste de titres observé
Résumé des preuves
The domain kcn.co.com is currently active and classified as a high‑risk brand‑impersonation campaign targeting Google. According to the latest intelligence (July 24 2026), the site presents the page title “AF88 Kcn - Trang Chủ Chính Thức AF88.COM - Nhà Cái Uy Tín”, which does not reference Google but the domain is listed as impersonating the Google brand. The domain was registered on 16 August 1997 through Moniker Online Services LLC and uses the nameservers ns1.nic.co.com through ns4.nic.co.com. Infrastructure analysis shows the domain resolves to 172.67.222.103, an IP owned by Cloudflare, Inc. (AS13335) located in the United States.
HTTP requests return a 301 redirect, and the TLS certificate is issued by Google Trust Services under the WE1 profile, suggesting an attempt to lend credibility to the site. Security telemetry indicates the domain appears on four blocklists – PhishDestroy, Polkadot, Enkrypt, and Codeesura – and has a Gridinsoft trust score of 0 out of 100. VirusTotal reports three detections out of ninety‑one scanned vendors, reinforcing the malicious assessment. The web stack is identified as WordPress running on MySQL and PHP, with client‑side libraries including jQuery, jQuery Migrate, HSTS, and Cloudflare Browser Insights, confirming the use of a typical content‑management platform behind Cloudflare protection.
The campaign is categorized as credential phishing, although the exact phishing vector (login page, credential‑stealing form, etc.) has not been publicly disclosed. Defenders should block the domain at DNS and proxy layers, enforce URL filtering against the listed blocklists, and monitor for any outbound connections to the associated Cloudflare IP. Incident response teams should also consider reviewing logs for attempts to access Google‑related services from internal users, as the impersonation may aim to harvest Google credentials.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
7 sources externes surveillées Aucune correspondance
Chronologie de détection
-
État du domaine
Accessible → Inaccessible
-
État du domaine
Inaccessible → Accessible
-
État du domaine
Inaccessible → Accessible
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of kcn.co.com · checked Mar 5, 2026
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif