secure-eng-kucoin[.]framer[.]ai
“KuCoin® Sign-In Portal | Your Gateway to Advanced Trading⢔
secure-eng-kucoin.framer.ai — Неперевірений. Уособлення бренду: KuCoin; Тип шахрайства: Impersonation. Зведення доказів: VirusTotal 11/91 (alphaMountain.ai, ESET, Emsisoft, Forcepoint ThreatSeeker, Fortinet); URLScan malicious verdict; PhishDestroy score 83/100. Реєстратор: Framer.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of the domain secure-eng-kucoin.framer.ai, observed on 5 August 2026, classifies it as a credential‑phishing infrastructure. Registration data show the domain was created through Framer B.V., a registrar associated with the framer.ai sub‑domain space. The domain resolves to the single IPv4 address 31.43.160.6; no nameserver records were returned during lookup, indicating either misconfiguration or deliberate concealment of DNS infrastructure. Automated scanning on VirusTotal involved 91 antivirus and URL‑reputation engines; none reported a detection, but the absence of a flag does not constitute evidence of benign intent.
The domain is currently listed on one public security blocklist and has been actively blocked by the PhishDestroy sinkhole, confirming that threat‑intel feeds have identified it as malicious. The campaign remains active, with the risk level marked as “under investigation” by internal tracking. Observed indicators suggest that the operator is leveraging the framer.ai hosting platform to host credential‑phishing pages, likely targeting users of the KuCoin cryptocurrency exchange, as implied by the domain label.
Defensive recommendations include adding the domain and its resolving IP address to outbound and inbound firewall deny lists, updating URL filtering policies, and ensuring that endpoint protection solutions receive the latest threat‑intel feeds. Continuous monitoring of DNS queries for the domain and periodic re‑scanning with sandbox tools are advised to detect any changes in payload or hosting configuration. Organizations should also educate users about unsolicited login requests that reference KuCoin and encourage verification of URLs before credential entry.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com 100% впевненостіReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of secure-eng-kucoin.framer.ai · checked Aug 5, 2026
Аналіз конфігурації сайту
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога