help-sin-com-coinbase[.]framer[.]media
“Site Not Found | Framer”
ملخص الأدلة
This domain, help-sin-com-coinbase.framer.media, is flagged as a high-risk credential harvesting site targeting Coinbase users. Analysis indicates a deliberate brand impersonation campaign designed to deceive victims into submitting login credentials, recovery phrases, or two-factor authentication codes under the pretense of account verification or security alerts. The threat type is classified as brand impersonation with a secondary vector of cryptocurrency theft, given the targeted platform’s association with digital asset management. Infrastructure analysis reveals multiple technical indicators supporting this assessment. The domain was registered on February 21, 2026, through CSC Corporate Domains, Inc., and currently resolves to the IP address 31.43.160.6, hosted on Amazon.com, Inc. infrastructure (AS16509) in the Netherlands. The SSL certificate is issued by Let's Encrypt (serial number E7), a common choice for malicious actors due to its low-cost and automated issuance process. Detection metrics further corroborate the malicious nature of the domain: 17 out of 95 security vendors on VirusTotal flagged it as phishing, while Google Safe Browsing explicitly classified it as a phishing threat. Additionally, the domain appears on one security blocklist and was proactively blocked by PhishDestroy. The page title, 'Site Not Found | Framer,' suggests an attempt to obfuscate its true purpose, likely after takedown or during evasion efforts. Mitigation against this threat requires a multi-layered approach. Organizations should immediately update web filtering rules to block access to help-sin-com-coinbase.framer.media and its resolving IP, 31.43.160.6, at the network perimeter. End-users who may have interacted with the domain should be instructed to reset Coinbase credentials using a verified device and enable hardware-based multi-factor authentication. Security teams are advised to monitor for indicators of compromise, including anomalous login attempts or unauthorized cryptocurrency transactions, particularly for accounts linked to the targeted brand. Given the domain’s registration through a corporate registrar, further investigation into the registration details may uncover additional infrastructure tied to the same threat actor. Proactive threat hunting for related domains using similar naming conventions (e.g., 'help-sin-com-[brand]') is recommended to preemptively disrupt follow-on campaigns.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
التقنيات
حُدّدت ٤ تقنيات عالية الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of help-sin-com-coinbase.framer.media · checked Mar 2, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب