The domain kconnlogoc.webflow.io is currently active and resolves to the IP address 104.18.36.248. Registration information shows that the domain was created through Webflow, Inc., and no public nameserver records were returned. The domain is listed on a single security blocklist and is actively blocked by PhishDestroy. VirusTotal analysis shows that 10 of 91 security vendors have flagged the domain as malicious, indicating a moderate level of detection confidence.
The detection count of ten out of ninety‑one vendors suggests that a subset of scanning engines have identified malicious patterns, such as known phishing URLs or suspicious hosting characteristics, while the majority have not yet flagged the site, which is typical for newly registered or low‑profile phishing domains. The presence of multiple vendor detections, combined with its inclusion on a blocklist, supports the classification of the site as a generic phishing infrastructure. No additional intelligence such as SSL certificate details, HTTP response codes, page title, or brand targeting is currently available, leaving the exact content of the hosted page unverified. Because the site is hosted on a shared Webflow infrastructure, the underlying TLS certificate is owned by the platform and does not provide domain‑specific validation, limiting the ability to assess certificate reputation.
Defenders are advised to add kconnlogoc.webflow.io to network‑level deny lists, update URL filtering rules, and monitor for any outbound connections to the associated IP address. Organizations employing web‑proxy or secure web‑gateway solutions should ensure that the URL is categorized as malicious and enforce block actions, and incident response teams should consider the domain as a potential indicator of compromise when observed in logs. Continuous re‑evaluation is recommended in case additional telemetry becomes available.