coinbase-pro-secure[.]framer[.]ai
“Site Not Found | Framer”
ملخص الأدلة
The domain coinbase-pro-secure.framer.ai was registered on January 06, 2018 through CSC Corporate Domains, Inc. and is presently taken offline, returning an HTTP 404 response with the page title "Site Not Found | Framer". Technical fingerprinting shows the site was hosted on Amazon Web Services (ASN16509) in the Netherlands, resolving to IP address 31.43.160.6. The certificate presented was issued by Let’s Encrypt (E8), and the service stack included Framer Sites, React, HSTS, and HTTP/3. A scan on VirusTotal recorded 15 detections out of 93 analyzing engines, indicating a moderate level of malicious confidence.
Google Safe Browsing classifies the URL as a social engineering threat, and the domain appears on a single security blocklist, where it has been actively blocked by PhishDestroy. The domain purpose is identified as a crypto scam impersonating the Coinbase brand, though the exact payload or credential‑stealing mechanism has not been captured. Evidence confirms the domain resolves to a legitimate AWS IP range, suggesting the attackers leveraged reputable cloud infrastructure to lend credibility.
No additional intelligence, such as phishing page screenshots or malware samples, is currently available. Defenders should continue to block the domain at network perimeters, monitor DNS queries for the associated IP and name server set (ns-1902.awsdns-45.co.uk, ns-635.awsdns-15.net, ns-1198.awsdns-21.org), and update endpoint protection signatures to incorporate the observed VirusTotal detections. Because the site is offline, active exploitation is unlikely, but the infrastructure could be repurposed for future campaigns; continuous vigilance on the AWS host and associated certificate is advised.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
التقنيات
حُدّدت ٤ تقنيات عالية الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of coinbase-pro-secure.framer.ai · checked Mar 2, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب