Analysis as of July 30, 2026 indicates that kuwqnlogin.webflow.io is an active credential‑phishing infrastructure. The domain was registered through Webflow, Inc., a SaaS website builder that also provides DNS hosting. DNS resolution currently points to the IP address 172.64.151.8. The domain is listed on two public phishing blocklists and is actively blocked by PhishDestroy and OpenPhish, confirming that it is recognized as malicious by multiple threat‑intelligence feeds. VirusTotal reports that 17 of 91 scanning engines have flagged the domain as malicious, reinforcing the high‑risk assessment.
No page title or content analysis is available at this time, and the nameserver information could not be retrieved. The domain’s presence on reputable blocklists such as PhishDestroy and OpenPhish suggests that it has been observed delivering credential‑harvesting pages to unsuspecting users. The fact that 17 independent scanners on VirusTotal have raised detections indicates that static or dynamic analysis has identified malicious patterns, though the exact payload has not been publicly disclosed. Because the domain resolves to a single IP address, network‑level controls can effectively block traffic to that host. However, the underlying hosting service (Webflow) may host many legitimate sites, so blanket blocking of the entire provider is not advisable; instead, rule‑based filtering should target the specific hostname or IP.
Organizations should also review outbound traffic logs for connections to 172.64.151.8 and correlate with user reports of phishing emails that reference login pages. Defenders should add kuwqnlogin.webflow.io to URL filtering and DNS‑blocking policies, consider blocking the associated IP address, and monitor for any newly observed hostnames that resolve to the same address.