base-browser-extension[.]pages[.]dev
“Coinbase Wallet Extension - Secure Web3 Access”
This domain, base-browser-extension.pages.dev, is flagged as an active brand impersonation threat targeting Coinbase users. Analysis indicates the page masquerades as the Coinbase Wallet Extension under the title 'Coinbase Wallet Extension - Secure Web3 Access,' attempting to deceive users into installing malicious browser components. The infrastructure appears designed to harvest cryptocurrency wallet credentials or deploy crypto drainer functionality, though no specific drainer kit signature has been confirmed at this time. Infrastructure analysis reveals the domain was registered through Cloudflare on March 25, 2026, resolving to IP address 172.66.47.49 (Cloudflare, Inc., CA). The domain appears on one security blocklist and is flagged by 6 of 95 security vendors on VirusTotal. The SSL certificate is issued by Google Trust Services (WE1), a common pattern observed in both legitimate and malicious Cloudflare-hosted domains. No Google Safe Browsing detections were reported at the time of analysis. The domain remains active as of the latest verification, though it has been blocked by at least one security provider. Response actions should include immediate blacklisting of the domain and IP across security gateways, as well as monitoring for related subdomains or newly registered lookalike domains. Users are advised to verify browser extensions exclusively through official vendor marketplaces and to inspect SSL certificates for anomalies. The remaining risk is classified as high due to the domain's active status and direct targeting of cryptocurrency wallet credentials, which could lead to immediate financial loss if successful.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
10 مصادر · تمت المزامنة في 09/08/2026
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of base-browser-extension.pages.dev · checked Apr 2, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب