kcn[.]co[.]com
Перевірка домену kcn.co.com на фішинг і безпеку
“AF88 Kcn - Trang Chủ Chính Thức AF88.COM - Nhà Cái Uy Tín”
kcn.co.com — Останній відомий активний (HTTP 301). Уособлення бренду: Google; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 3/91 (alphaMountain.ai, Chong Lua Dao, Gridinsoft); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 84/100. Реєстратор: Moniker Online Services.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain kcn.co.com is currently active and classified as a high‑risk brand‑impersonation campaign targeting Google. According to the latest intelligence (July 24 2026), the site presents the page title “AF88 Kcn - Trang Chủ Chính Thức AF88.COM - Nhà Cái Uy Tín”, which does not reference Google but the domain is listed as impersonating the Google brand. The domain was registered on 16 August 1997 through Moniker Online Services LLC and uses the nameservers ns1.nic.co.com through ns4.nic.co.com. Infrastructure analysis shows the domain resolves to 172.67.222.103, an IP owned by Cloudflare, Inc. (AS13335) located in the United States.
HTTP requests return a 301 redirect, and the TLS certificate is issued by Google Trust Services under the WE1 profile, suggesting an attempt to lend credibility to the site. Security telemetry indicates the domain appears on four blocklists – PhishDestroy, Polkadot, Enkrypt, and Codeesura – and has a Gridinsoft trust score of 0 out of 100. VirusTotal reports three detections out of ninety‑one scanned vendors, reinforcing the malicious assessment. The web stack is identified as WordPress running on MySQL and PHP, with client‑side libraries including jQuery, jQuery Migrate, HSTS, and Cloudflare Browser Insights, confirming the use of a typical content‑management platform behind Cloudflare protection.
The campaign is categorized as credential phishing, although the exact phishing vector (login page, credential‑stealing form, etc.) has not been publicly disclosed. Defenders should block the domain at DNS and proxy layers, enforce URL filtering against the listed blocklists, and monitor for any outbound connections to the associated Cloudflare IP. Incident response teams should also consider reviewing logs for attempts to access Google‑related services from internal users, as the impersonation may aim to harvest Google credentials.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 9 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
Plugin to detect and restore deprecated jQuery features.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of kcn.co.com · checked Mar 5, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога