kuwqnlogin.webflow.io
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of kuwqnlogin.webflow.io
This domain appears to be a page hosted on the Webflow platform that presents itself as a KuCoin login or sign-up page for cryptocurrency trading. The page title and meta description reference KuCoin directly, and the screenshot shows KuCoin branding, crypto-related marketing text, and account-access prompts intended to resemble a cryptocurrency exchange landing page.
Based on the domain structure, this does not appear to be an official primary KuCoin domain, but rather a third-party subdomain on webflow.io. The content suggests the page is designed to attract users looking to access a crypto trading account, which places it in a high-risk context because login-themed pages for financial or crypto services are commonly used to capture credentials or redirect visitors to harmful destinations.
Safety Assessment for kuwqnlogin.webflow.io
Multiple warning signals were present at the time of this scan. The domain was flagged by 17 out of 91 security engines, with many of those detections classifying it as phishing or malicious. In addition, the page content closely imitates KuCoin branding while using an unrelated Webflow subdomain, which may indicate a look-alike page intended to resemble a legitimate cryptocurrency platform. The malware scan also identified a flagged outbound link and referenced domain associated with a malicious object.
Blacklist and reputation data were mixed rather than fully clean. Major content-malice databases listed in the scan did not report the domain at that moment, but the domain's IP address was listed on one mail-reputation blocklist, which is a weaker signal and does not by itself prove harmful website content. Even so, that DNS-based listing adds a small amount of caution rather than reassurance.
Taken together, the combination of multi-engine phishing detections, brand imitation indicators, and a flagged external destination suggests elevated risk for visitors, especially anyone entering credentials or wallet-related information. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was served over HTTPS with a valid TLS certificate issued by Google Trust Services, expiring on 2026-10-23. It appears to be proxied through Cloudflare and hosted on Cloudflare infrastructure, with the observed server IP geolocating to Toronto, Canada. The page also loads static assets from Webflow-related content delivery domains and CloudFront.
DNSSEC appears to be unsigned, which is not uncommon but does mean DNS responses do not benefit from DNSSEC validation. From a security perspective, the main concern in this scan was not the TLS setup itself, but the mismatch between the hosted subdomain and the branded login-style content, along with the flagged outbound link to an external domain identified as malicious during the scan.
Share your experience with this website. Was it safe? Did you encounter any issues?