sso--netcoins-com--cdn-oauth[.]webflow[.]io
“sso--netcoins-com--cdn-oauth.webflow.io”
sso--netcoins-com--cdn-oauth.webflow.io — Неперевірений. Зведення доказів: VirusTotal 18/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); CF Radar malicious; PhishDestroy score 100/100. Реєстратор: Webflow.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain is flagged as a generic phishing site with an elevated risk level, specifically designed to harvest user credentials through deceptive single sign-on (SSO) interfaces. Analysis indicates the infrastructure was constructed to mimic legitimate authentication portals, likely targeting users of financial or cryptocurrency services by exploiting trust in SSO workflows. Infrastructure analysis reveals the domain sso--netcoins-com--cdn-oauth.webflow.io is currently offline but was previously hosted on IP address 104.18.36.248, geolocated in the United States under AS13335 (Cloudflare, Inc.). The domain appears on at least one security blocklist and is registered through Webflow, a platform commonly abused for rapid deployment of phishing pages. VirusTotal detection metrics show 19 out of 95 security vendors flagging the domain as malicious, with a focus on credential theft. The page title, identical to the domain name, suggests a lack of legitimate branding, further indicating fraudulent intent. Mitigation against this threat type requires immediate action from both end-users and security teams. Users who accessed the domain should rotate all credentials entered, particularly those associated with financial or cryptocurrency accounts, and enable multi-factor authentication (MFA) where available. Security teams should block the domain and its resolving IP (104.18.36.248) at the network perimeter, monitor for related indicators of compromise (IOCs), and conduct retrospective analysis to identify any prior interactions with the domain. Given the use of Cloudflare infrastructure, additional scrutiny of domains with similar naming patterns (e.g., sso--[service]--cdn-oauth) is recommended to preemptively disrupt copycat campaigns.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Технології · 3 identified
Visual website builder with hosted publishing.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of sso--netcoins-com--cdn-oauth.webflow.io · checked Mar 18, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога