kucienlogoenz[.]webflow[.]io
“Kucoin Login: Accessing Your Kucoin Account - Webflow”
kucienlogoenz.webflow.io — Контент недоступен. Олицетворение бренда: Kucoin; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 16/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Регистратор: MarkMonitor.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain kucienlogoenz.webflow.io is associated with a confirmed cryptocurrency‑related impersonation campaign targeting the Kucoin exchange. The site resolves to the Cloudflare address 104.18.36.248, which is advertised as belonging to AS13335 Cloudflare, Inc. and is geolocated in the United States. Registration data shows the domain was created on 08 May 2013 and is managed through MarkMonitor, Inc., a registrar commonly used by legitimate brands, indicating that the attackers deliberately leveraged a reputable registrar to increase perceived legitimacy. DNS resolution is performed via Cloudflare’s authoritative nameservers journey.ns.cloudflare.com and lamar.ns.cloudflare.com, and the TLS certificate presented is issued by Google Trust Services under the WE1 trust bundle, further mimicking a trustworthy environment.
The web content served a page titled “Kucoin Login: Accessing Your Kucoin Account - Webflow”, explicitly referencing the Kucoin brand and aligning with the declared scam type of a crypto scam. HTTP response code 403 suggests the site is currently inaccessible, and its operational status is listed as offline. Nonetheless, threat‑intel feeds have recorded the domain as active in the recent past: 16 of 95 VirusTotal scanners flagged the host, it appears on a single security blocklist, and PhishDestroy has added it to its block list. Detected technologies include Webflow, Cloudflare, and HTTP/3, indicating a modern hosting stack.
While the site is presently taken offline, the combination of a brand‑specific title, legitimate registrar usage, Cloudflare hosting, and multiple vendor detections provides strong evidence of a targeted crypto‑phishing operation. Uncertainty remains regarding the exact content that was delivered before takedown and whether additional infrastructure (e.g., command‑and‑control servers or credential‑harvesting endpoints) was employed.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 3 identified
Webflow is Software-as-a-Service (SaaS) for website building and hosting.
webflow.com 100% уверенностиCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание