kconnlign[.]webflow[.]io
Analyse phishing et sécurité de kconnlign.webflow.io
“Kucoin *Login: Accessing Your Kucoin Account”
kconnlign.webflow.io — Contenu indisponible (HTTP 404). Usurpation de l'identité de la marque : KuCoin; Type d'arnaque : Crypto Scam. Résumé des preuves: VirusTotal 17/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, Certego, CRDF); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Bureau d’enregistrement: MarkMonitor.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Analysis
This domain, kconnlign.webflow.io, operates as a brand impersonation site designed to deceive users into disclosing login credentials for KuCoin, a major cryptocurrency exchange. The site presents a fraudulent login interface titled 'Kucoin *Login: Accessing Your Kucoin Account,' closely mimicking the legitimate platform's design to trick victims into entering sensitive account details. Such attacks typically lead to unauthorized access, financial theft, or further exploitation through malware deployment, particularly targeting users with active crypto holdings. Analysis indicates the domain was created on May 8, 2013, though the phishing content appears to have been hosted recently under the subdomain structure of webflow.io. The domain resolves to the IP address 104.18.36.248, associated with Cloudflare, Inc. (AS13335) in the United States. It is registered through MarkMonitor, Inc., a registrar commonly used for both legitimate and malicious domains. Security vendors have flagged the domain, with 17 out of 95 engines on VirusTotal detecting it as malicious. Additionally, the domain appears on two security blocklists: PhishDestroy and PhishingDB, further confirming its fraudulent nature. Users who visited kconnlign.webflow.io should immediately take corrective actions to mitigate potential risks. First, reset passwords for KuCoin and any other accounts where identical or similar credentials were used. Enable multi-factor authentication (MFA) on all financial and crypto-related platforms to add an extra layer of security. Monitor accounts for unauthorized transactions or suspicious activity, and report any anomalies to the affected service provider. If personal or financial information was entered, consider contacting relevant institutions to place fraud alerts on accounts. Finally, scan devices for malware using updated security tools to ensure no additional compromise occurred.
Couverture des données12 recorded checks
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externesIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.