login-coinbas-io[.]pages[.]dev
“Suspected phishing site | Cloudflare”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
Analysis of the domain login-coinbas-io.pages.dev, created on 21 February 2026 and registered via Cloudflare, Inc., indicates a confirmed brand‑impersonation campaign targeting Coinbase users. The site resolves to the Cloudflare edge address 172.66.47.100, located in the United States under ASN 13335. HTTP requests receive a 403 status code and the page title returned by the server is “Suspected phishing site | Cloudflare”, which matches the classification used by the hosting provider. The TLS certificate is issued by Google Trust Services under the WE1 root, confirming the use of a legitimate SSL chain but offering no protection against malicious content. Infrastructure fingerprints show the presence of HSTS, Cloudflare services, and HTTP/3, all typical of legitimate Cloudflare‑proxied sites and therefore not indicative of a compromised origin.
Security‑vendor scans on VirusTotal show that 15 of 93 AV engines flag the domain as malicious, reinforcing the suspicion. Independent blocklists record the domain on one active list, and the anti‑phishing service PhishDestroy has already taken the site offline. The domain’s nameservers, novalee.ns.cloudflare.com and giancarlo.ns.cloudflare.com, are standard Cloudflare delegations. A Gridinsoft trust score of 0 / 100 further reflects a high confidence of malicious intent. The site is explicitly labeled as a “Brand Impersonation” and is noted to impersonate Coinbase, though no additional content analysis is available.
Uncertainty remains regarding the exact payload or credential‑harvesting mechanisms, as no page content has been captured beyond the generic title. Defenders should continue to block the domain at perimeter devices, monitor DNS queries for the domain and its associated IP address, and add the host to internal blocklists. Organizations should also alert users about the risk of unsolicited login prompts referencing Coinbase and advise verification of URLs before credential entry.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
المخطط الزمني للاكتشاف
الاستخبارات الجنائية الرقمية
التقنيات
حُدّدت ٣ تقنيات عالية الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of login-coinbas-io.pages.dev · checked Mar 2, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب