sales-batch[.]coinbase[.]com[.]lc
“sales-batch.coinbase.com.lc”
اكتشاف محفوظ
تنبيه إخفاء المحتوى
- نوع الإخفاء
content_divergence- درجة الإخفاء
- 2/6
ملخص الأدلة
sales-batch.coinbase.com.lc is currently flagged as a high‑risk brand‑impersonation site targeting Coinbase customers. The domain resolves to the IPv4 address 75.2.18.233 and is hosted within Amazon’s AS16509 network in the United States. An analysis of the TLS certificate shows a valid Let’s Encrypt R13 certificate, and the web server advertises Nginx and OpenResty. HTTP requests return a 200 status code, indicating an active web service.
Security telemetry reports that ten of ninety‑five VirusTotal scanners have marked the domain as malicious, while Google Safe Browsing classifies it under the SOCIAL_ENGINEERING category. The Gridinsoft trust score is 0 out of 100, and the domain appears on one external blocklist. Registration metadata points to the AMAZO‑4 registrar, reinforcing the association with ASN 16509. PhishDestroy has already added the domain to its blocklist, confirming that defensive operators have recognized its malicious intent.
The available intelligence does not include a visual or content analysis of the landing page beyond the title “sales‑batch.coinbase.com.lc,” nor does it reveal the exact payload or credential‑collection mechanism employed. Consequently, the precise tactics used to lure victims—whether login harvesters, crypto‑wallet prompts, or other fraud vectors—remain unconfirmed. Continuous monitoring of the host infrastructure and any associated DNS records is advisable to detect potential shifts in activity.
Defenders should immediately block the domain name and its resolved IP address at perimeter firewalls and DNS filtering layers. Inclusion of the IPv4 host in threat‑intelligence feeds and endpoint allow‑list exclusions will prevent inadvertent access. Organizations should alert users to the specific impersonation of Coinbase and advise verification of URLs before entering any account information. Reporting the indicator to additional malware‑tracking platforms will aid in broader community mitigation.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of sales-batch.coinbase.com.lc · checked Mar 2, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب