conbase-authenticated-appdashboardweb[.]duia[.]ro
“Coinbase - Sign In”
ملخص الأدلة
The domain conbase-authenticated-appdashboardweb.duia.ro is flagged as a Coinbase impersonation used for a crypto‑scam operation. Registration records show the domain was created on 31 August 2011 and is listed under the registrar CYBER_FOLKS S.R.L., indicating a long‑standing registration that predates the recent activity. The authoritative name servers are ns1.duiadns.net and ns2.duiadns.net, both associated with the duia.ro zone. Network analysis reveals the domain resolves to the IPv4 address 130.94.12.172, which belongs to AS154177 (LIGHT NODE LIMITED) and is geolocated in the United States. No TLS certificate is presented; the site is served over plain HTTP, a typical characteristic of fraudulent credential‑harvesting pages. The page title returned by the web server is “Coinbase – Sign In”, directly mirroring the legitimate brand’s login portal.
Reputation services provide strong evidence of malicious intent. The domain appears on a single security blocklist, where it is listed by PhishDestroy. Gridinsoft assigns a trust score of 0 out of 100, the lowest possible rating. VirusTotal reports that 14 of 93 scanners flag the domain as malicious, reinforcing the suspicion. The overall classification from the supplied intelligence is a “Crypto Scam”, confirming that the site is likely intended to capture cryptocurrency‑related credentials or to lure victims into fraudulent transactions. The current operational status is offline, which may be a temporary takedown or a shift to a different hosting location.
Defenders should continue to block the domain at perimeter firewalls, DNS filters, and proxy devices. Because the domain resolves to an IP owned by a public cloud provider, additional monitoring of the IP address for any future re‑use is advisable. Threat‑intel feeds that incorporate the registrar, name‑server, and ASN information can be enriched to catch any new domains created by the same entity.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب