kukonihlogin[.]webflow[.]io
“ꝄuCoin® Login - Accessing Your KuCōin Account Easily**”
kukonihlogin.webflow.io — 内容不可用. 品牌冒充:Genericcrypto; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 17/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. 注册商: NameCheap.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, kukonihlogin.webflow.io, is identified as a credential phishing resource targeting users of the cryptocurrency exchange KuCoin. The page impersonates the legitimate KuCoin login interface, presenting a fraudulent portal titled 'ꝄuCoin® Login - Accessing Your KuCōin Account Easily.' The substitution of Unicode characters (Ꝅ and ō) in the title suggests an attempt to evade basic detection mechanisms while maintaining visual similarity to the authentic brand. No direct evidence of a cryptocurrency drainer kit was observed, though credential harvesting remains the primary objective, potentially leading to unauthorized access to user funds or personal data. Infrastructure analysis reveals the following technical indicators: the domain was registered through NameCheap, Inc. on February 21, 2026, and resolves to the IP address 104.18.36.248, associated with AS13335 Cloudflare, Inc. in the United States. Detection metrics indicate elevated risk, with 17 out of 95 security vendors on VirusTotal flagging the domain as malicious. The domain appears on a single security blocklist and was actively blocked by PhishDestroy. The SSL certificate is issued by Google Trust Services (WE1), a common practice among phishing operators to lend an appearance of legitimacy. As of the latest assessment, the domain has been taken offline, reducing immediate exposure to end users. However, the infrastructure remains a residual risk, as threat actors frequently repurpose or re-deploy similar domains under different names. Users who may have interacted with this resource are advised to revoke any active sessions, reset credentials, and monitor associated accounts for unauthorized activity. Organizations should update blocklists to include the domain and IP address, while security teams should investigate potential lateral movement from compromised credentials. The use of Unicode spoofing in the page title underscores the need for enhanced detection mechanisms capable of identifying homoglyph-based impersonation tactics.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
所用技术 · 3 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of kukonihlogin.webflow.io · checked Mar 1, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。