user-coinbsepro[.]pages[.]dev
فحص التصيد والأمان للنطاق user-coinbsepro.pages.dev
“Suspected phishing site | Cloudflare”
user-coinbsepro.pages.dev — يمكن الوصول إليها · الوصول مقيد (HTTP 403). انتحال العلامة التجارية: Genericcloudflare; نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 13/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); URLScan malicious verdict; PhishDestroy score 89/100. مسجّل النطاق: Cloudflare.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, user-coinbsepro.pages.dev, is flagged as a crypto-focused phishing site designed to impersonate legitimate cryptocurrency exchange platforms. Analysis indicates the infrastructure was likely established to deploy a wallet drainer kit, targeting users attempting to access trading or account management interfaces. The domain mimics branding elements associated with major exchanges, though no direct trademark infringement has been confirmed. The page title, 'Suspected phishing site | Cloudflare,' suggests automated detection by the hosting provider prior to takedown, though no specific phishing kit signature has been attributed at this time. Technical indicators reveal the domain was registered through Cloudflare, Inc. on October 17, 2025, and resolves to the IP address 172.66.44.99, geolocated to the United States under AS13335. The SSL certificate is issued by Google Trust Services (WE1), a common configuration for Cloudflare-hosted domains. Security telemetry shows the domain appears on one blocklist and is detected by 13 out of 95 security vendors on VirusTotal. No Google Safe Browsing (GSB) listing is recorded, though this may reflect latency in propagation rather than absence of detection. The domain's creation date and rapid inclusion in blocklists suggest a short-lived, high-velocity campaign typical of opportunistic phishing operations. As of the latest assessment, user-coinbsepro.pages.dev has been taken offline, likely following reports to the hosting provider or registrar. The domain is blocked by PhishDestroy and other security feeds, reducing immediate exposure risk. However, residual threats persist, including potential reuse of the underlying infrastructure or migration of the phishing kit to newly registered domains. Users who interacted with the site prior to takedown should assume credential or wallet compromise and conduct a full security review, including revocation of active sessions, password resets, and transaction history audits. Organizations should monitor for related domains leveraging similar naming conventions or hosting patterns, particularly those using Cloudflare Pages or subdomains under .pages.dev.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
الاستخبارات الجنائية الرقمية
التقنيات · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of user-coinbsepro.pages.dev · checked Apr 13, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب