dcit323coinbase[.]netlify[.]app
“coinbase-clone”
ملخص الأدلة
This domain is classified as a high-risk brand impersonation threat targeting Coinbase users. Analysis indicates the site is designed to harvest login credentials, recovery phrases, or facilitate unauthorized cryptocurrency transactions under the guise of the legitimate platform. The domain employs deceptive branding elements, including a page title labeled 'coinbase-clone,' to mislead victims into believing they are interacting with an official service. Infrastructure analysis reveals the domain dcit323coinbase.netlify.app is hosted on Netlify infrastructure, resolving to IP address 63.176.8.218 within the DE region under AS16509 (Amazon.com, Inc.). The SSL certificate is issued by DigiCert Inc, specifically a DigiCert Global G2 TLS RSA SHA256 2020 CA1, which does not mitigate the malicious intent. The domain was registered on March 12, 2026, and remains active despite being flagged by 11 out of 95 security vendors on VirusTotal. Additionally, it appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL, further confirming its malicious classification. Mitigation steps for this brand impersonation threat include immediate blocking of the domain and its associated IP (63.176.8.218) at the network perimeter. Security teams should deploy indicators of compromise (IOCs) such as the domain name, IP, and SSL certificate details into endpoint detection and response (EDR) systems. Users should be educated to verify domain authenticity by checking for official SSL certificates and avoiding interaction with sites using unofficial hosting platforms (e.g., Netlify for financial services). Multi-factor authentication (MFA) should be enforced for all cryptocurrency-related accounts to reduce the risk of credential compromise.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 10/08/2026
المخطط الزمني للاكتشاف
-
VirusTotal
0 ← 5
التقنيات
حُدّدت ٤ تقنيات عالية الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of dcit323coinbase.netlify.app · checked Mar 12, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب