kucoinoxc[.]nilcat[.]cn
“KuCoin”
kucoinoxc.nilcat.cn — 内容不可用. 品牌冒充:KuCoin; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 19 detections (engine total unavailable) (ADMINUSLabs, Criminal IP, BitDefender, Cluster25, CRDF); URLQuery 5 alerts; CF Radar malicious; PhishDestroy score 95/100. 注册商: 邦宁数字技术股份有限公司.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, kucoinoxc.nilcat.cn, poses a direct threat as a brand impersonation site targeting KuCoin, a major cryptocurrency exchange. The site is designed to deceive users into entering login credentials or wallet details, likely facilitating unauthorized access to accounts or direct crypto asset theft. The page title explicitly replicates KuCoin’s branding, increasing the likelihood of successful social engineering attacks against users familiar with the legitimate platform.
Analysis of technical indicators reveals significant red flags. The domain was registered on March 14, 2026, through 邦宁数字技术股份有限公司, and resolves to the IP address 180.97.215.93, located within AS4134 (CHINANET-BACKBONE). It is currently flagged by 19 out of 95 security vendors on VirusTotal, and appears on at least one security blocklist. The domain’s SSL certificate, issued by Let’s Encrypt (R13), provides encryption but does not mitigate the underlying malicious intent. Infrastructure analysis indicates the site was operational long enough to pose a credible threat before being taken offline.
Users who visited kucoinoxc.nilcat.cn or entered credentials on the site should take immediate action. First, revoke any active sessions on the legitimate KuCoin platform and reset passwords using multi-factor authentication (MFA). Monitor all linked accounts, including email and connected wallets, for unauthorized transactions. If cryptocurrency was transferred or wallet details were shared, consider moving assets to a new, secure wallet. Report the incident to KuCoin’s official security team and relevant authorities to assist in tracking the threat. Future vigilance is critical, as similar domains may emerge using comparable naming conventions or infrastructure.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | kucoinoxc.nilcat.cn |
phishing | Phishing Block |
| Cloudflare DNS | kucoinoxc.nilcat.cn |
malicious | Sinkholed |
| Hagezi Threat Feed | kucoinoxc.nilcat.cn |
malicious | Sinkholed |
| DNS4EU | kucoinoxc.nilcat.cn |
malicious | Sinkholed |
| Quad9 DNS | kucoinoxc.nilcat.cn |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 5 identified
Progressive JavaScript framework for building user interfaces.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of kucoinoxc.nilcat.cn · checked Mar 14, 2026
证据与外部报告
PD-20260314-65AF2A Recipient: thanhtram02061991@gmail.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。