welcome-coinbase-cdn[.]wstd[.]io
welcome-coinbase-cdn.wstd.io — لم يتم التحقق منها. انتحال العلامة التجارية: Coinbase; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 12/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, CyRadar, Fortinet); Google Safe Browsing flagged; PhishDestroy score 86/100. مسجّل النطاق: NameCheap.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis indicates that the domain welcome-coinbase-cdn.wstd.io was registered on February 21, 2026 through NameCheap, Inc. The authoritative name servers are sandra.ns.cloudflare.com and cosmin.ns.cloudflare.com, both associated with Cloudflare’s DNS service. DNS resolution points to IP address 104.19.163.34, which belongs to AS13335 Cloudflare, Inc., and is geolocated in the United States. The site presented an HTTPS certificate issued by Let’s Encrypt (identifier E8), confirming the use of a free TLS certificate. An HTTP request to the host returned a 401 Unauthorized status, suggesting that the server is configured to require authentication, but no content was retrieved before the domain was taken offline. Google Safe Browsing has classified the URL under social engineering, and the domain appears on one external security blocklist.
PhishDestroy has also added it to its blocklist, indicating that it was recognized as a malicious resource. The Gridinsoft trust score is 0 out of 100, reinforcing the low credibility of the infrastructure. VirusTotal analysis shows that 12 out of 93 scanning engines flagged the domain as malicious, providing independent corroboration of its threat posture. The domain’s branding references Coinbase, and the intelligence tags it as a crypto‑related scam. The combination of brand impersonation, the presence of a free TLS certificate, and the alignment with known crypto‑scam infrastructure points to a likely credential‑harvesting or fund‑diversion campaign targeting Coinbase users.
Because the site is currently offline, payload or page‑level details cannot be verified, leaving the exact phishing vector uncertain. Defenders should immediately block resolution of welcome-coinbase-cdn.wstd.io at network perimeter and add the associated IP 104.19.163.34 to deny‑list rules, noting that Cloudflare may host multiple unrelated customers. Continuous monitoring of the IP range for reappearance of similar domains is recommended.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب