EN ES PT
Back to Stats

Visual Capture

Screenshot of kconnlogonb.webflow.io

Detection Info

http://kconnlogonb.webflow.io/
Detected Brand
KuCoin
Country
International
Confidence
100%
HTTP Status
200
Report ID
cb92ac96-546โ€ฆ
Analyzed
2026-02-18 01:31
Final URL (after redirects)
https://kconnlogonb.webflow.io/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T198D1753BD24863360761C0A0B99B23C9E36B544D83718BDB49F8D48C27B9F31997A5DB
CONTENT ssdeep
192:0kwgwnTPCwb6H6Rt6H6D634o9SOu25E8PlfK8LV:0kwgwn7CwbSStS6U4jEFNpLV

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
a42499d8dcee9b83
VISUAL aHash
c3030383f77fff7f
VISUAL dHash
96164e262ed9c7f2
VISUAL wHash
c3030383073f3f3f
VISUAL colorHash
06038000000
VISUAL cropResistant
96164e262ed9c7f2

Code Analysis

Risk Score 68/100
Threat Level ALTO
โš ๏ธ Phishing Confirmed
๐ŸŽฃ Credential Harvester ๐ŸŽฃ Banking

๐Ÿ”ฌ Threat Analysis Report

โ€ข Threat: Phishing
โ€ข Target: KuCoin users
โ€ข Method: Impersonation via a fake login page.
โ€ข Exfil: Likely steals login credentials (email/password).
โ€ข Indicators: Free hosting, brand logo, forms.
โ€ข Risk: HIGH

๐Ÿ”’ Obfuscation Detected

  • fromCharCode

๐ŸŽฏ Kit Endpoints

  • https://kconnlogonb.webflow.io/

๐Ÿ“Š Risk Score Breakdown

Total Risk Score
95/100

Contributing Factors

Free Hosting
The domain uses free hosting, which is a major red flag.
Brand Impersonation
The site mimics the branding of a legitimate company (KuCoin).
Forms Present
The site contains a form to collect user data

๐Ÿ”ฌ Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
KuCoin users (International)
Attack Method
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

โš ๏ธ Indicators of Compromise

  • Kit types: Credential Harvester, Banking
  • 4 obfuscation techniques

๐Ÿข Brand Impersonation Analysis

Impersonated Brand
KuCoin
Official Website
https://www.kucoin.com/
Fake Service
KuCoin Login/Account Registration

โš”๏ธ Attack Methodology

Primary Method: Credential Harvesting

The attacker aims to steal user credentials by creating a fake login page that mimics the official KuCoin login page.

Secondary Method: Social Engineering

The page is designed to appear legitimate, potentially tricking users into entering their login credentials.

๐ŸŒ Infrastructure Indicators of Compromise

Domain Information

Domain
kconnlogonb.webflow.io
Registered
Unknown
Registrar
Unknown
Status
Active

๐Ÿ”ฌ JavaScript Deep Analysis

Sophistication Level
Basic
Total Code Size
36.5ย KB

๐Ÿ”— API Endpoints Detected

Other
4
Backend API
1

๐Ÿ” Obfuscation Detected

  • : Light

๐Ÿค– AI-Extracted Threat Intelligence

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

๐Ÿ˜ฐ
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.