suportkucon[.]webflow[.]io
“KuCoin ℓoℊin || Exchange Your Cryptocurrency”
suportkucon.webflow.io — Контент недоступний. Уособлення бренду: KuCoin; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 16/94 (ADMINUSLabs, alphaMountain.ai, Chong Lua Dao, CyRadar, Emsisoft); URLQuery 3 alerts; URLScan malicious verdict; PhishDestroy score 95/100. Реєстратор: MarkMonitor.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain suportkucon.webflow.io was registered on March 6, 2026 through MarkMonitor, Inc. The site presented a page titled “KuCoin ℓoℊin || Exchange Your Cryptocurrency,” indicating a brand‑impersonation campaign aimed at KuCoin users. TLS termination is handled by Cloudflare, as evidenced by the Google Trust Services / WE1 SSL certificate, and the domain resolves to IP address 104.18.36.248, which belongs to ASN 13335 (Cloudflare, Inc.) and is geolocated in the United States. VirusTotal analysis recorded 16 detections out of 94 security vendors, reflecting a consensus that the domain is malicious. It appears on one public blocklist and has been blocked by PhishDestroy.
The HTTP response returned a 404 status code, and the current operational status is offline. The available intelligence points to a crypto‑scam using a Webflow subdomain to host a counterfeit login portal. While the page title confirms the impersonation intent, the full page content, payload, and any downstream infrastructure have not been captured, leaving those aspects uncertain. No additional indicators such as malware hashes or command‑and‑control servers have been disclosed.
Defenders should add the domain and its resolved IP to network blocklists, update email and web gateway filters with the observed page title, and monitor for future registrations that reuse the same registrar or Cloudflare edge IP range. Authentication attempts to KuCoin originating from this IP or containing the identified title pattern should be flagged for further investigation. Ongoing monitoring of VirusTotal and related threat‑intel feeds is recommended to track any evolution of the campaign.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | suportkucon.webflow.io |
malicious | Sinkholed |
| OpenDNS | suportkucon.webflow.io |
phishing | Phishing Block |
| DNS4EU | suportkucon.webflow.io |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога