sso--secure--coinbasepro-cdn-i-autth[.]webflow[.]io
“404 - Page not found”
sso--secure--coinbasepro-cdn-i-autth.webflow.io — المحتوى غير متوفر. انتحال العلامة التجارية: Coinbase; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 13/93 (ADMINUSLabs, BitDefender, CyRadar, ESET, Emsisoft); Google Safe Browsing flagged; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 89/100. مسجّل النطاق: Cloudflare.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain sso--secure--coinbasepro-cdn-i-autth.webflow.io was registered on March 02, 2026 and is currently taken offline. Infrastructure analysis shows the domain resolves to IP address 104.18.36.248, which belongs to AS13335 owned by Cloudflare, Inc., located in the United States. The site presents a SSL certificate issued by Google Trust Services under the WE1 authority, indicating the use of standard web‑hosting TLS provisioning rather than a custom or self‑signed certificate. The observed HTTP response code is 404 and the page title returned is "404 - Page not found," suggesting the malicious content has been removed or the site has been deliberately disabled.
Detection data indicates that 13 of 93 security vendors on VirusTotal flagged the domain, and Google Safe Browsing classifies it as a social engineering threat. The domain appears on three external blocklists and has been actively blocked by PhishDestroy, MetaMask, and SEAL. The listed scam type is a crypto scam, and the domain impersonates the Coinbase brand, which aligns with the known intent to lure victims into credential or wallet compromise. Technologies detected include Cloudflare services and HTTP/3 support, confirming the use of a modern CDN for delivery.
While the site is no longer serving content, the presence of the domain in multiple blocklists and the detection count demonstrate that it was previously considered malicious. Defenders should continue to enforce blocklist rules that include this domain, monitor for any re‑registration attempts on similar sub‑domains, and maintain vigilance for outbound connections to the 104.18.36.248 address, especially from endpoints that handle cryptocurrency assets. Additionally, security teams should update phishing awareness material to reference this specific impersonation of Coinbase, reinforcing that legitimate Coinbase communications never originate from a webflow.io sub‑domain.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
الأدلة المؤرشفة
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of sso--secure--coinbasepro-cdn-i-autth.webflow.io · checked Mar 2, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب