kucoin-lxgen[.]gitbook[.]io
“kucoin @ Login”
kucoin-lxgen.gitbook.io — Скрытый · достижимый. Олицетворение бренда: KuCoin; Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLQuery 3 alerts; URLScan malicious verdict; CF Radar malicious; cloaking observed; PhishDestroy score 100/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain is flagged as an elevated-risk brand impersonation threat targeting KuCoin, a cryptocurrency exchange platform. Analysis indicates the site operates as a credential harvesting portal, presenting a login interface under the title 'kucoin @ Login' to deceive users into submitting sensitive authentication details. The infrastructure and content are designed to mimic legitimate KuCoin services, increasing the likelihood of successful compromise for unsuspecting victims. Infrastructure analysis reveals the domain kucoin-lxgen.gitbook.io was registered through Cloudflare, Inc. and resolves to the IP address 104.18.40.47, located in Canada under Cloudflare’s network. The domain was originally created on March 30, 2014, though the current malicious activity suggests recent repurposing. Security vendor detection on VirusTotal stands at 18 out of 95 engines, indicating moderate but notable consensus regarding its malicious nature. The domain appears on one security blocklist, and its SSL certificate is issued by Google Trust Services (WE1), a common provider for both legitimate and malicious sites. The page title explicitly references KuCoin, reinforcing the brand impersonation tactic. Mitigation against this threat involves immediate domain blacklisting at the network and endpoint levels, particularly for entities handling cryptocurrency transactions. Organizations should update detection rules to flag domains hosted on 104.18.40.47 or associated with Cloudflare registrations exhibiting brand impersonation patterns. User education should emphasize verifying domain authenticity before entering credentials, especially for financial or cryptocurrency platforms. Monitoring for similar domains registered under GitBook or Cloudflare infrastructure may help preempt future campaigns leveraging the same tactics.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | kucoin-lxgen.gitbook.io |
malicious | Sinkholed |
| Cloudflare DNS | kucoin-lxgen.gitbook.io |
malicious | Sinkholed |
| DNS4EU | kucoin-lxgen.gitbook.io |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 6 identified
GitBook is a command-line tool for creating documentation using Git and Markdown.
www.gitbook.com 100% уверенностиHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиGoogle Cloud Trace is a distributed tracing system that collects latency data from applications and displays it in the Google Cloud Console.
cloud.google.com 100% уверенностиCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of kucoin-lxgen.gitbook.io · checked Apr 29, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание