begin-coinbase-wallet-extension[.]pages[.]dev
“begin-coinbase-wallet-extension.pages.dev”
Gespeicherte Beobachtung
Beobachteter Titelkontrast
Zusammenfassung der Beweislage
The domain begin-coinbase-wallet-extension.pages.dev was registered on February 21, 2026 and is hosted behind Cloudflare’s network, resolving to IP address 172.66.44.103 located in Canada. The authoritative nameservers are paris.ns.cloudflare.com and west.ns.cloudflare.com, confirming Cloudflare as the registrar. The site presents a page title identical to the fully qualified domain name and is currently returning HTTP 403, indicating that the content is not publicly reachable; the domain has been taken offline by the operators. Multiple security services have flagged the domain. Google Safe Browsing classifies it as a social engineering threat, and PhishDestroy lists it as blocked.
It appears on one additional security blocklist. VirusTotal reports that 11 of 93 scanning engines have flagged the domain, reinforcing the malicious assessment. Reputation services are extremely low: Gridinsoft assigns a trust score of 0 / 100 and Scamadviser a score of 1 / 100. The page is identified as a crypto scam that impersonates the Coinbase brand, matching the declared brand target. Detected infrastructure technologies include HSTS, Cloudflare, and HTTP/3, all typical of legitimate services but also used to lend credibility to fraudulent sites.
The precise content of the page has not been captured, so the exact phishing mechanisms or credential‑stealing forms remain unknown. Defenders should add the domain to internal blocklists, monitor DNS queries for the associated Cloudflare IP range, and enforce outbound filtering that blocks connections to this host. Given the Google Safe Browsing and VirusTotal detections, security solutions that integrate these feeds will already flag the domain, but manual policies should be reinforced to prevent any residual traffic from reaching end users. Continuous observation of Cloudflare‑hosted domains that mimic financial brands is advised, as the infrastructure can be rapidly reused for new campaigns.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 12.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
Domainstatus
Erreichbar → Nicht erreichbar
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
Forensische Erkenntnisse
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of begin-coinbase-wallet-extension.pages.dev · checked Apr 13, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt