coinexapp[.]ru
“CoinEx ™ | The Official Site 【UPDATED 2025】”
Gespeicherte Erkennung
Cloaking-Warnung
- Cloaking-Typ
status_split- Cloaking-Wert
- 2/6
Zusammenfassung der Beweislage
Analysis of coinexapp.ru indicates a high‑confidence brand‑impersonation threat targeting users of the CoinEx platform. The domain was registered on May 27, 2025 through the BEGET‑RU registrar and is hosted on the IP address 91.236.116.114, which belongs to AS42237 w1n ltd in Sweden. The name servers ns1.ns8t7.com and ns2.ns8t7.com resolve to the same IP, and no TLS certificate is presented, meaning the site operates without HTTPS protection. The page title returned by the server reads "CoinEx ™ | The Official Site 【UPDATED 2025】", directly mirroring the legitimate brand’s branding and reinforcing the impersonation claim.
Gridinsoft assigns a trust score of 0 / 100, and the domain appears on one security blocklist, confirming that at least one protective feed has flagged it. PhishDestroy has already taken the domain offline, and AlienVault OTX includes it in a single threat‑intel pulse, providing additional corroboration from the threat‑sharing community. VirusTotal reports that 16 of 95 scanned security vendors flag the domain as malicious, indicating a consensus among multiple detection engines. The combination of a brand‑specific page title, lack of encryption, low trust score, and multiple independent detections suggests the infrastructure was deliberately crafted for credential harvesting or fraud.
Defenders should update their URL filtering rules to block coinexapp.ru, ensure that any outbound connections to the associated IP address are denied, and monitor for any residual traffic that may still be attempting to reach the host. Because the site is currently offline, ongoing observation is needed to detect possible re‑hosting under a different IP or domain. Organizations should also educate users about the risk of unsolicited links claiming to be official CoinEx communications, emphasizing verification of TLS certificates and the importance of accessing the service only through known, trusted URLs.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt