kkuiionlog-iim[.]godaddysites[.]com
“Kucoin Loℊin | Loℊ In Kucoin”
kkuiionlog-iim.godaddysites.com — Непроверенный. Олицетворение бренда: KuCoin; Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 18/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, ESET, Emsisoft); PhishDestroy score 95/100. Регистратор: GoDaddy Sites.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain kkuiionlog-iim.godaddysites.com has been identified as a credential phishing portal specifically impersonating the KuCoin cryptocurrency exchange login interface. Analysis confirms the domain currently exhibits an offline status, though prior activity targeted users attempting to access legitimate KuCoin services through deceptive login prompts. The page title, Kucoin Loℊin | Loℊ In Kucoin, employs homoglyph substitution (replacing 'g' with 'ℊ') to evade basic detection mechanisms and mimic the authentic platform’s branding. Infrastructure analysis reveals the domain was registered through GoDaddy Sites, with a creation date of May 27, 2026, indicating a likely typographical error in the registration timestamp or an attempt to obfuscate tracking. The domain resolves to the IP address 76.223.105.230 and is associated with an SSL certificate issued by GoDaddy.com, Inc. under the Go Daddy Secure Certificate Authority - G2. Security vendor detection metrics report 17 of 95 engines on VirusTotal flagging the domain as malicious, while it appears on a single security blocklist, specifically PhishDestroy. The elevated detection rate, despite limited blocklist inclusion, suggests a targeted or recently deployed campaign. Current status indicates the domain has been taken offline, likely due to enforcement actions or infrastructure suspension. However, the technical indicators—including the homoglyph usage, anomalous creation date, and SSL certificate issuer—warrant continued monitoring. Organizations and users are advised to implement strict domain validation protocols, particularly for cryptocurrency-related services, and to verify SSL certificate chains independently. Network-level blocking of the identified IP (76.223.105.230) and domain is recommended as a precautionary measure. End-users should be trained to recognize homoglyph attacks and report suspicious login portals to security teams for further analysis.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: godaddysites.com
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain godaddysites.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание