MALICIOUS — CRITICAL
coinpool[.]app
3 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); the latest stored check returned HTTP 200.
- VirusTotal
- 3/91
- Blocklists
- 2 · MetaMask, SEAL
- التوفر
- آخر نشاط معروف · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
coinpool.app — آخر نشاط معروف (HTTP 200). نوع الاحتيال: Crypto Drainer. ملخص الأدلة: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. مسجّل النطاق: Name.com.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Digest
coinpool.app has a stored critical classification with an evidence score of 83/100. 3 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL). Registered 11 May 2026 via Name.com, Inc., hosted on 188.114.96.3 (Cloudflare, Inc., CA). The latest stored check on 9 Aug 2026 returned HTTP 200.
Stored generated summary (templated)mistral · 13/07/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
This domain, coinpool.app, is actively flagged as a high-risk crypto drainer phishing site. Registered on May 11, 2026, through Name.com, Inc., it resolves to IP address 188.114.96.3, hosted behind Cloudflare infrastructure in Canada. The domain is currently served by Cloudflare nameservers (hadlee.ns.cloudflare.com, nash.ns.cloudflare.com) and returns an HTTP 200 status, indicating an operational endpoint. Analysis of threat intelligence sources reveals the domain appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL, and is linked to one AlienVault OTX pulse. The page title, COINPOOL, aligns with the reported scam type, suggesting a focus on cryptocurrency theft. Only one of 92 security vendors on VirusTotal has flagged this domain, which may reflect limited detection coverage rather than low risk. The SSL certificate is issued by Google Trust Services (WE1), a common but not inherently malicious provider. Defenders should treat this domain as an active threat, particularly in environments handling cryptocurrency transactions. Blocking the domain and associated IP (188.114.96.3) is recommended, along with monitoring for connections to the nameservers or certificate authority. Further analysis of the site’s content or payload is needed to confirm specific attack vectors, but the available indicators confirm its classification as a crypto drainer.
نطاق تغطية البيانات12 recorded checks
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.