get-coinbs--extension[.]pages[.]dev
“Suspected phishing site | Cloudflare”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
This domain, get-coinbs--extension.pages.dev, is identified as a crypto wallet drainer phishing site designed to steal cryptocurrency credentials and assets. Analysis indicates the infrastructure was actively targeting users through deceptive wallet extension prompts, likely mimicking legitimate browser-based crypto wallet services. The domain is currently offline, though prior activity suggests it was operational for malicious purposes. Infrastructure analysis reveals the domain was registered through Cloudflare, Inc. on February 21, 2026, and resolved to the IP address 188.114.96.3, hosted on AS13335 (Cloudflare, Inc.) in the United States. The SSL certificate is issued by Google Trust Services (WE1), a common characteristic of phishing domains leveraging legitimate certificate authorities. Security vendors flagged the domain as malicious, with 14 of 95 VirusTotal engines detecting it as phishing. Additionally, the domain appears on one security blocklist and was explicitly flagged by Google Safe Browsing as a phishing threat. The page title, 'Suspected phishing site | Cloudflare,' further corroborates its malicious classification, as this is a default warning for domains suspended or detected by Cloudflare’s abuse systems. The domain’s current offline status reduces immediate risk, but historical activity and infrastructure characteristics warrant caution. Users who interacted with this domain should assume credential compromise and take immediate action, including revoking wallet permissions, transferring assets to a secure wallet, and monitoring for unauthorized transactions. Organizations should update blocklists to include this domain and its associated IP address (188.114.96.3) to prevent future access. Security teams are advised to review logs for connections to this domain and investigate potential lateral movement or data exfiltration tied to its use. Proactive monitoring of newly registered domains with similar patterns (e.g., Cloudflare Pages subdomains, crypto-related keywords) is recommended to mitigate emerging threats.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
المخطط الزمني للاكتشاف
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of get-coinbs--extension.pages.dev · checked Apr 13, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب