v0-coinbasevaultsetup[.]vercel[.]app
“Coinbase Vault”
Zusammenfassung der Beweislage
The domain v0-coinbasevaultsetup.vercel.app was observed delivering a brand‑impersonation payload that mimics Coinbase’s Vault service. DNS resolution points to the IP address 216.198.79.67, which is registered to Amazon.com, Inc. (AS16509) and geolocated in the United States. The site is hosted on Vercel infrastructure, as indicated by the “Vercel” technology fingerprint and the presence of an HSTS header. SSL termination is provided by Google Trust Services under the WR1 certificate chain, confirming that a valid public certificate is in use. Google Safe Browsing classifies the URL as a social‑engineering threat, and VirusTotal reports that 12 of 95 scanning engines flag the domain as malicious, reflecting a moderate to high confidence of abuse.
The domain appears on a single external blocklist and has been actively blocked by PhishDestroy, reinforcing its malicious reputation. An HTTP 451 response code was returned at the time of testing, indicating that the resource is unavailable for legal reasons, consistent with the current offline status. The page title “Coinbase Vault” aligns with the declared brand target of Coinbase and the listed scam type of “Crypto Scam”. Registration information shows the domain was provisioned through Vercel Inc., a legitimate SaaS provider, which does not imply endorsement of the content.
No further content analysis is available because the site is offline. Defenders should add 216.198.79.67 to network‑level deny lists, enforce DNS filtering for the full domain, and monitor for any future re‑registration on similar Vercel sub‑domains. Continuous observation of Google Safe Browsing and VirusTotal alerts is recommended to capture any resurgence. Organizations that use Coinbase services should educate users about unsolicited requests that reference a “Vault” and verify URLs against the official Coinbase domain before entering credentials.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 12.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
Domainstatus
Erreichbar → Nicht erreichbar
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of v0-coinbasevaultsetup.vercel.app · checked Mar 2, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt