help-coinbse-pros-en[.]framer[.]media
“Coinbase Pro Login Help | Access Your Crypto Trading Dashboard”
help-coinbse-pros-en.framer.media — المحتوى غير متوفر. انتحال العلامة التجارية: Coinbase; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 7/95 (ChainPatrol, alphaMountain.ai, Certego, CyRadar, Ermes); Google Safe Browsing flagged; PhishDestroy score 80/100. مسجّل النطاق: CSC.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis indicates that the domain help-coinbse-pros-en.framer.media is actively used to impersonate Coinbase, specifically targeting users of Coinbase Pro. The site presents a page title “Coinbase Pro Login Help | Access Your Crypto Trading Dashboard”, which aligns with the advertised brand impersonation. Technical checks reveal that the domain resolves to the IPv4 address 35.71.142.77, an Amazon Web Services host located in the United States and announced by ASN 16509 (Amazon.com, Inc.). The hosting environment serves the site over HTTPS using a Let’s Encrypt certificate (issuer “E7”), and the server announces HSTS and HTTP/3 support. Fingerprinting tools identified the presence of Framer Sites and a React front‑end, consistent with the use of a popular website‑building platform.
The domain was registered on 19 November 2021 through CSC Corporate Domains, Inc., and is delegated to four AWS name servers (ns‑1267.awsdns-30.org, ns‑535.awsdns-02.net, ns‑97.awsdns-12.com, ns‑1854.awsdns-39). HTTP probing returned a 404 status code, suggesting that the malicious landing page may have been removed or is otherwise inaccessible at the time of testing. Nevertheless, the site is listed on at least one external blocklist and has been actively flagged by PhishDestroy. Google Safe Browsing classifies the URL as a social‑engineering threat, and VirusTotal reports that seven of ninety‑five scanning engines flagged the domain, reinforcing the malicious assessment. The current operational status is “offline”, indicating that the hosting may have been taken down or temporarily suspended.
However, the infrastructure—particularly the AWS IP address and the publicly available certificate—remains reusable for future campaigns. Defenders should continue to monitor the IP 35.71.142.77 and the associated AWS name servers for re‑appearance of similar payloads.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com ثقة 100٪React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org ثقة 100٪HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
الأدلة المؤرشفة
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of help-coinbse-pros-en.framer.media · checked Jun 27, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب