help-coinbase-secure[.]framer[.]media
“Coinbase - Sign in”
Gespeicherte Beobachtung
Beobachteter Titelkontrast
Zusammenfassung der Beweislage
Analysis of help-coinbase-secure.framer.media shows a high‑risk brand‑impersonation operation targeting Coinbase users. The domain was registered through CSC Corporate Domains, Inc. and created on 19 November 2021. It resolves to the Amazon Web Services address 35.71.142.77, located in the United States and advertised under ASN 16509 (Amazon.com, Inc.). The hosting environment uses Let’s Encrypt certificate issued to the domain, with HSTS and HTTP/3 enabled, and the site stack is identified as Framer Sites running React.
The page title returned by the server is “Coinbase – Sign in”, directly mirroring the legitimate brand’s login page, which aligns with the listed scam type “Crypto Scam”. Google Safe Browsing has flagged the domain for social engineering, and 16 of 93 security vendors on VirusTotal have generated detections. PhishDestroy has taken the site offline, and the domain currently returns an HTTP 404 response. It appears on a single external blocklist, and the domain is listed in one additional security blocklist.
The combination of brand‑specific page title, the use of a reputable SSL certificate, and the presence of modern web technologies suggests a deliberately crafted impersonation site designed to harvest Coinbase credentials. Because the site is already offline, immediate containment actions are limited to ensuring that any cached copies or redirects are removed from corporate web filters. Defensive teams should add the domain and its associated IP address to URL filtering and indicator‑of‑compromise (IOC) lists, monitor for any resurgence of similar Framer‑based impersonation domains, and enforce multi‑factor authentication for Coinbase accounts to mitigate credential reuse. Continuous observation of the registrar CSC Corporate Domains, Inc. and the AWS name‑server set (ns‑1267.awsdns‑30.org, ns‑1854.awsdns‑39.co.uk, ns‑535.awsdns‑02.net, ns‑97.awsdns‑…) is recommended to detect future registrations that may reuse the same infrastructure.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 12.08.2026
Erkennungszeitleiste
-
Domainstatus
Erreichbar → Nicht erreichbar
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of help-coinbase-secure.framer.media · checked Mar 2, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt