wildcard[.]791826coinbase[.]com
“Plesk Obsidian 18.0.74”
wildcard.791826coinbase.com — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Coinbase; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 8/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, CRDF, CyRadar); Spamhaus DBL_PHISH; PhishDestroy score 74/100.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain wildcard.791826coinbase.com was registered on February 21, 2026 and is presently taken offline. Infrastructure analysis shows the domain resolves to the IP address 172.203.144.85, which belongs to the AS8075 Microsoft Corporation network located in the United States. The hosting environment presents a Plesk Obsidian 18.0.74 control panel, as indicated by the page title returned from the server. An SSL certificate labeled “R13” is associated with the domain, confirming that HTTPS was provisioned, but the certificate details have not been disclosed.
The domain is flagged by eight of ninety‑three VirusTotal scanners, and it appears on a single external security blocklist. PhishDestroy has listed the domain as blocked, and Gridinsoft assigns it a trust score of zero out of one hundred, reflecting an extremely low confidence rating. The intelligence attributes the site to a crypto‑scam campaign that impersonates the Coinbase brand, consistent with the “Crypto Scam” classification supplied.
While the available data confirms the domain’s creation date, hosting provider, SSL presence, and detection metrics, no public content analysis or visual inspection has been performed, leaving the exact malicious payload or credential‑harvesting mechanism unverified. Defenders should immediately add the domain and its resolved IP address to network blocklists, enforce DNS sink‑holing for the name, and monitor for any resurgence of activity. Continuous re‑scanning with multi‑vendor sandboxes is advised to capture any evolving payloads, and threat‑intel feeds should be updated to reflect the current offline status while retaining historical indicators for future correlation.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب