web-ext-coin-pro[.]pages[.]dev
فحص التصيد والأمان للنطاق web-ext-coin-pro.pages.dev
“Coinbase Chrome Extension - Secure Crypto Access™”
web-ext-coin-pro.pages.dev — يمكن الوصول إليها · الوصول مقيد (HTTP 403). انتحال العلامة التجارية: Coinbase; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 1/94 (LevelBlue); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 71/100. مسجّل النطاق: Cloudflare.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy identifies the active domain web-ext-coin-pro.pages.dev as a generic phishing host designed to harvest Web3 wallet credentials under the guise of a bogus browser extension. The page mimics legitimate crypto tools, luring victims with promises of enhanced functionality while secretly exfiltrating private keys and seed phrases. Evidence suggests a drainer kit is in use, though the exact payload remains under analysis. This campaign targets users searching for Chrome or Firefox extensions that interact with blockchain networks, with traffic likely driven by SEO poisoning and paid ads pointing to the Cloudflare Pages subdomain. The threat is categorized as credential theft with potential fund loss once wallets are compromised.
Technical indicators confirm the following: the domain resolves to IP 172.66.47.50, is registered through Cloudflare, Inc., and secured with a Google Trust Services SSL certificate. VirusTotal currently shows 1/95 detections, indicating it remains undetected by most antivirus engines. The domain is served from Cloudflare Pages, a platform often abused by threat actors for rapid deployment and bulletproof hosting. Although the creation date is not publicly available due to Cloudflare’s privacy protections, the active status and zero detections imply recent deployment. Google Safe Browsing (GSB) has not yet flagged the domain, and no public blocklists currently include it. These factors contribute to a high dwell time, increasing the risk of successful victim engagement.
The domain remains active and under investigation, with the current risk level classified as 'under_investigation.' PhishDestroy continues to monitor the host via behavioral analysis and sandbox detonation to identify new payloads or infrastructure pivots. Users are advised to avoid visiting web-ext-coin-pro.pages.dev or any related links offering 'crypto extensions.' Validate browser add-ons exclusively through official stores and verify developer credentials. Organizations should implement DNS filtering rules to block the IP 172.66.47.50 and monitor internal endpoints for outbound connections to this domain. Remaining risk is assessed as elevated due to the lack of detection coverage and ongoing operational status.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة المؤرشفة
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of web-ext-coin-pro.pages.dev · checked Apr 13, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب