auth--kucoin-helpp[.]webflow[.]io
“Sign In to Your Account™ : Kucoin | Login”
auth--kucoin-helpp.webflow.io — Неперевірений. Уособлення бренду: KuCoin; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 19/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 2 alerts; URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 100/100. Реєстратор: Webflow.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies the domain auth--kucoin-helpp.webflow.io as an active brand impersonation site currently impersonating the global cryptocurrency exchange KuCoin. The infrastructure is classified as an elevated-risk threat with confirmed malicious intent targeting users through deceptive replication of KuCoin’s brand assets and support interfaces. This domain has been assessed as active and remains accessible to visitors, posing imminent danger to individuals seeking legitimate customer support or login portals.
This domain was flagged by 20 of 95 VirusTotal security vendors and resolves to IP address 104.18.36.248. The domain is hosted on Webflow and secured with a Google Trust Services SSL certificate, which does not indicate legitimacy given the malicious content. Security telemetry indicates this infrastructure is part of a broader wave of KuCoin impersonation campaigns observed since early 2024, often leveraging typosquatting and lookalike branding to harvest credentials and initiate crypto drainage via fake withdrawal pages.
The current status of auth--kucoin-helpp.webflow.io is active and operational. PhishDestroy strongly recommends immediate network and user-level defensive actions: block the domain and IP (104.18.36.248) at the firewall and DNS level, update threat intelligence feeds, and issue advisories to users advising against interaction. Organizations should also monitor endpoints for signs of credential compromise or crypto wallet access. This domain exemplifies the sophistication of modern crypto drainers and reinforces the need for continuous monitoring and user security awareness training focused on brand impersonation and support scams.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | auth--kucoin-helpp.webflow.io |
malicious | Sinkholed |
| OpenDNS | auth--kucoin-helpp.webflow.io |
phishing | Phishing Block |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
Webflow is Software-as-a-Service (SaaS) for website building and hosting.
webflow.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of auth--kucoin-helpp.webflow.io · checked Apr 23, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога