kiichainio[.]pages[.]dev
“KiiChain”
证据摘要
This domain is flagged as an active crypto wallet drainer phishing threat targeting users of the KiiChain platform. Analysis indicates the infrastructure is designed to mimic legitimate blockchain services, likely to trick victims into connecting wallets and authorizing malicious transactions, resulting in unauthorized fund transfers. Infrastructure analysis reveals the domain kiichainio.pages.dev was registered on April 02, 2026, through Cloudflare, Inc. It resolves to the IP address 172.66.44.190, hosted in Canada under Cloudflare’s network. The SSL certificate is issued by Let’s Encrypt (serial number E8). As of the latest scan, VirusTotal reports 0 detections out of 95 engines, suggesting the threat is either new or employs evasion techniques. The domain appears on one security blocklist and is currently blocked by at least one threat intelligence feed. The page title, KiiChain, aligns with the impersonated brand, further confirming the targeted nature of this campaign. Mitigation steps for this specific threat type include immediate blocking of the domain and its resolving IP (172.66.44.190) at the network perimeter. Organizations should deploy endpoint protection rules to detect and prevent connections to newly registered domains hosted on Cloudflare’s infrastructure, particularly those mimicking blockchain services. Users should be educated to verify domain authenticity before connecting wallets, especially for platforms like KiiChain, and to use hardware wallets or isolated browser sessions for cryptocurrency transactions. Monitoring for unauthorized transaction signatures or unusual wallet activity is critical, as drainer scripts execute rapidly once permissions are granted.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
域名情报
技术详情DNS、TLS 名称和时间戳
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控