kucoincmlggin[.]webflow[.]io
“KuCōin® % Login - Bitcoin 💎 Crypto Exchange - us”
kucoincmlggin.webflow.io — Контент недоступен. Олицетворение бренда: KuCoin; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 20/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); CF Radar malicious; PhishDestroy score 95/100. Регистратор: MarkMonitor.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain kucoincmlggin.webflow.io is identified as a brand impersonation threat targeting KuCoin, a cryptocurrency exchange platform. Analysis indicates the domain was designed to mimic the official KuCoin login interface, likely to harvest user credentials or facilitate unauthorized account access. The page title, KuCōin® % Login - Bitcoin 💎 Crypto Exchange - us, employs Unicode characters to closely resemble the legitimate brand while evading basic detection mechanisms. The domain is currently offline, but prior activity warrants continued monitoring. Technical indicators confirm the domain's malicious nature. It was flagged by 20 of 95 security vendors on VirusTotal, with detections from multiple reputable engines. The domain was registered through MarkMonitor, Inc. on May 8, 2013, though the impersonation activity appears to be more recent. Infrastructure analysis reveals the domain resolved to IP address 172.64.151.8, hosted on Cloudflare's network (AS13335). The domain appears on two security blocklists, including PhishDestroy and PhishingDB. The SSL certificate, issued by Google Trust Services (WE1), does not mitigate the risk, as encryption is commonly exploited in phishing campaigns to appear legitimate. Current status indicates the domain has been taken offline, reducing immediate risk to users. However, the infrastructure and registration details suggest potential for re-emergence under a similar or altered domain. Organizations and individuals are advised to block the domain and its associated IP address at the network level. Users who may have interacted with the domain should immediately reset their KuCoin credentials and enable multi-factor authentication. Security teams should monitor for domains with similar naming patterns, particularly those using Unicode characters or slight misspellings of the KuCoin brand. Proactive threat hunting for related indicators of compromise is recommended to identify any residual exposure.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 3 identified
Webflow is Software-as-a-Service (SaaS) for website building and hosting.
webflow.com 100% уверенностиCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of kucoincmlggin.webflow.io · checked Mar 1, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание