الانتقال إلى تقرير الأمان
Checked 09/08/2026 Ref C6BDEF87

MALICIOUS — CRITICAL

فحص التصيد والأمان للنطاق ext-conbasee.framer.ai

ext-conbasee[.]framer[.]ai

PhishDestroy identifies ext-conbasee.framer.ai as an active Coinbase-brand impersonation phishing campaign under investigation, posing as a fraudulent 'Coinbase Extension – Secure Web3 Wallet' web page.

95/100 evidence score · Critical
VirusTotal
16/94
Blocklists
2 · MetaMask, SEAL
التوفر
المحتوى غير متوفر · HTTP 404
Report / Add Evidence Appeal this listing
2026-04-11 13:01 UTCالمحتوى غير متوفر · HTTP 404

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 16. قوائم الحظر العامة التي تبلغ عن تطابق: 2. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
Jump to section
ملخص التقرير

ext-conbasee.framer.ai — المحتوى غير متوفر (HTTP 404). انتحال العلامة التجارية: Coinbase; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 16/94 (ChainPatrol, Chong Lua Dao, CRDF, CyRadar, ESET); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. مسجّل النطاق: CSC.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

Evidence Analysis

Ref C6BDEF87

PhishDestroy identifies ext-conbasee.framer.ai as an active Coinbase-brand impersonation phishing campaign under investigation, posing as a fraudulent 'Coinbase Extension – Secure Web3 Wallet' web page. The domain’s low detection rate and deliberate mimicry of a major cryptocurrency brand indicate a high-risk attempt to harvest user credentials and Web3 wallet access. This threat is not merely generic phishing—it is a targeted brand impersonation attack designed to exploit trust in Coinbase’s name and deceive users into installing malicious browser extensions or surrendering sensitive wallet recovery phrases. The risk level remains under investigation due to evolving infrastructure, but current indicators strongly suggest malicious intent and potential for widespread compromise.

This domain was flagged by PhishDestroy’s seed c6bdef with the following technical indicators: it resolves to IP address 31.43.161.6, hosts a Let’s Encrypt SSL certificate, and presents a page titled 'Coinbase Extension – Secure Web3 Wallet' on framer.ai’s subdomain platform. The domain currently shows 16/95 detections on VirusTotal, indicating no AV or security vendor flagging as of the latest scan. While registrar and creation date are not provided in open sources, the use of framer.ai’s platform and the immediate availability of the malicious page suggest rapid deployment for phishing purposes. It is not currently listed on major blocklists such as PhishTank, OpenPhish, or Google Safe Browsing, and WHOIS trust scores remain neutral due to the domain’s recent appearance.

To mitigate exposure to this specific threat, users must avoid accessing ext-conbasee.framer.ai or any framer.ai subdomain claiming to offer 'Coinbase Extensions' or 'Web3 Wallets.' Only download cryptocurrency-related software and browser extensions directly from the official Coinbase website (coinbase.com) or verified distribution points such as official app stores or GitHub under Coinbase’s verified account. Enable multi-factor authentication (MFA) on all crypto accounts and use hardware wallets for high-value assets. Security teams should block the IP 31.43.161.6 and monitor DNS for similar Coinbase-branded impersonations. Report any interactions with this domain to Coinbase’s abuse team and your internal security operations center. Always verify URLs via official sources before entering credentials or downloading software.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
16 det.
DNS Security
1/12
شهادة TLS
Let's Encrypt
العمر
4 mo
الحالة المرصودة
المحتوى غير متوفر 404
PhishDestroy
قائمة الإتلاف
مُدرج
Reports Sent
1
نطاق تغطية البيانات12 recorded checks
VirusTotal 16 / 94 URLQuery checked — no detections recorded PhishStats checked — no match recorded OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict malicious حجب عناوين DNS 1/12 TLS valid certificate, 46d WHOIS 4 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات
DNS Provider Blocks 1 / 12
Brand Base

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
15/15
تم استيعاب التهديد
ext-conbasee.framer.ai تم اكتشافها وإدراجها في قائمة الانتظار لإجراء تحليل شامل
11/04/2026
URLScan.io Capture
Stored URLScan report with capture artifacts
URLScan Verdict
URLScan returned a malicious verdict · score 100
29/07/2026
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
VirusTotal
16/94 recorded on VirusTotal
12/04/2026
Google Safe Browsing
11/04/2026
الكشف عن قوائم الحظر
موجود في 2 blocklists: MetaMask, SEAL
09/08/2026
DNS Security Blocks
Blocked by 1 of 12 checked DNS providers: Brand base
Brand Impersonation
Impersonation of Coinbase
Forensic Evidence Collected
Stored evidence from URLScan.io, URLQuery, stored screenshot
Technical Analysis Recorded
يحتوي التقرير على التكنولوجيا المخزنة أو نتائج تحليل الطب الشرعي.
09/08/2026
Sent Report Recorded
Stored sent-report record for registrar CSC Corporate Domains, Inc., hosting provider, 1 abuse contact
abuse@framer.com
11/04/2026
تم نشر قائمة «DestroyList»
11/04/2026
Content Observed Unavailable
تشير أحدث عمليات التحقق المخزنة إلى أن المحتوى الذي تم الإبلاغ عنه غير متوفر؛ هذا لا يحدد من أو ما سبب التغيير.
12/04/2026
الوقت حتى أول تعذّر للوصول
انقضت ساعات 32 منذ الكشف وحتى أول ملاحظة غير متاحة.

حالة قوائم الحظر العامة

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict ضار score 100 Phishing brand: Coinbase report ↗
الخادم / ASN Framer/154a7c5 · AS16509 Amazon.com, Inc.
سمعة عنوان IP abuse score 6/100 2 reports checked 14/07/2026
Registrar (base domain) CSC US(US)
جهة الإبلاغ عن إساءة الاستخدامabuse@framer.com
البحث في قاعدة بيانات WHOISICANN RDAP لـ framer.ai →
عنوان IP 31.43.161.6 NL
الموقع الجغرافيNL Amsterdam, NL
الشبكةAS16509 · Framer B.V
Registration (base domain)framer.ai · تم إنشاؤه 11/04/2026 (120d)
حالة HTTP404 Not Found
الوقت حتى أول تعذّر للوصول 32h
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف11/04/2026
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://ext-conbasee.framer.ai/
خوادم الأسماءns-114.awsdns-14.com
TLS Fingerprint
TLS Observationvalid from 26/02/2026scanned 11/04/2026
Case ID
عنوان الصفحة
Coinbase Extension – Secure Web3 Wallet
شهادة TLS
Valid transport encryption · صادرة عن Let's Encrypt · valid for 46 days
التقنيات · 4 identified
Framer Sites
React
JavaScript frameworks

JavaScript library for building user interfaces with component-based architecture.

HSTS
الأمن

HTTP Strict Transport Security — forces browsers to use HTTPS connections only.

HTTP/3
Miscellaneous

Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.

Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

16 / قام موردو الأمان 94 بوضع علامة على هذا المجال
View on VT
Last analyzed
ChainPatrol
Chong Lua Dao
CRDF
CyRadar
ESET
Emsisoft
Fortinet
G-Data
Gridinsoft
كاسبرسكي
LevelBlue
Lionic
نتكرافت
OpenPhish
سوفوس
Webroot
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260411-C6DFDB Recipient: abuse@framer.com
Page title stored with report: Coinbase Extension – Secure Web3 Wallet
نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك
تضمين هذا التقريرRead-only HTML widget
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/ext-conbasee.framer.ai"
  title="PhishDestroy threat report for ext-conbasee.framer.ai"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>