secure-io-qucion-sso[.]webflow[.]io
“Sign In | kUCOIN LOGIN*”
secure-io-qucion-sso.webflow.io — Контент недоступний. Уособлення бренду: Google; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 16/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Реєстратор: MarkMonitor.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain secure-io-qucion-sso.webflow.io was observed serving a page with the title "Sign In | kUCOIN LOGIN*" and is classified as a brand‑impersonation campaign targeting Google. Infrastructure analysis shows the domain resolves to 104.18.36.248, an address owned by AS13335 Cloudflare, Inc., located in the United States. The site is protected by a TLS certificate issued by Google Trust Services under the WE1 label, which may be intended to lend credibility to the fraudulent page. DNS resolution is handled by Cloudflare name servers journey.ns.cloudflare.com and lamar.ns.cloudflare.com, and the hosting stack includes Webflow and HTTP/3 support, indicating use of a commercial web‑app platform.
HTTP response code 403 was returned when the URL was accessed, and the domain has been taken offline as of the report date. VirusTotal scans recorded 16 detections out of 95 scanned engines, and the domain appears on one external security blocklist. PhishDestroy has already blocked the domain, and the registrar listed is MarkMonitor, Inc., a service often used for legitimate brand protection. The domain was originally registered on May 08 2013, suggesting the current malicious use may be a repurposed or hijacked resource.
While the page title and technical fingerprints are confirmed, the exact content of the landing page has not been captured, leaving the full scope of credential‑harvesting tactics uncertain. Defenders should continue to deny connections to 104.18.36.248, add secure-io-qucion-sso.webflow.io to URL filtering and email security policies, and monitor for similarly crafted subdomains that leverage Webflow and Cloudflare infrastructure. Ongoing vigilance is advised to detect any re‑activation or reuse of the domain under a different guise.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
Webflow is Software-as-a-Service (SaaS) for website building and hosting.
webflow.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога