# PhishDestroy threat dossier — 830129coinbase.com ================================================================ Fetched: 2026-07-27 01:35:32 UTC Canonical: https://phishdestroy.io/domain/830129coinbase.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 71/100 (PhishDestroy scoring — see methodology below) Targeted brand: Coinbase ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/91 security vendors flagged this domain Flagging vendors: ChainPatrol, ESET, Fortinet, Kaspersky Public blocklists: listed on 2 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 31.77.151.22 Registrar: Fewmoretaps OU d/b/a Trustname.com !!! REGISTRAR INTEGRITY ALERT — Trustname / Fewmoretaps OU !!! Trustname (IANA #4318) is a shell company declaring EUR 120 annual revenue, 1 employee, negative equity, Belarusian ownership. Explicitly advertises itself as 'bulletproof' in its DNS TXT records. Primary source: https://phishdestroy.io/trustname-bulletproof-exposed Nameservers: ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, zeus.trustname.com Registered: 2026-07-26 Expires: 2027-07-26 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-10-24 Status: INVALID chain Fingerprint: 49e91f0b59b3ad8048e71321ea679897f4ac84f8fc8648aad2520e91d1afb898 Subject Alternative Names (related infrastructure — often same operator): - www.830129coinbase.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-26 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 01:23:45 UTC (by PhishDestroy tracker) First reported: 2026-07-26 23:25:00 UTC (abuse notice filed) Last verified: 2026-07-27 03:03:11 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa0bd-3ed5-708d-8f86-19a6492b8320/ URLQuery: https://urlquery.net/report/a64504c0-85a1-4ec6-9539-bcce0e4c2c69 Wayback Machine: https://web.archive.org/web/*/830129coinbase.com crt.sh CT logs: https://crt.sh/?q=%25.830129coinbase.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=830129coinbase.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/830129coinbase.com URLhaus: https://urlhaus.abuse.ch/host/830129coinbase.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 01:27:12 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] 830129coinbase.com — Generic Phishing Investigation 830129coinbase.com was registered on July 26 2026 through Fewmoretaps OU d/b/a Trustname.com. The domain resolves to the IPv4 address 31.77.151.22 and is served by the nameservers ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz and zeus.trustname.com. Within the first day of appearance the domain was added to two security blocklists and is currently blocked by the PhishDestroy and SEAL filtering services. VirusTotal has recorded four positive detections out of ninety‑one scanners, indicating that a minority of AV engines have identified malicious activity associated with the host. The domain is classified as a generic phishing site and its risk rating is high; the status remains active. Analysis confirms that the infrastructure relies on shared DNS providers and a public IP that is not uniquely tied to a known malicious ASN in the available data. No SSL certificate details, HTTP response codes, page title, or additional threat‑intel such as OTX references are provided, leaving the content of the hosted site unverified. Consequently, defenders cannot assess the specific payload or credential‑harvesting mechanisms employed beyond the generic phishing attribution. Given the observed indicators, security teams should immediately add 830129coinbase.com to internal block or deny lists, monitor DNS queries for the listed nameservers, and enforce outbound filtering to the associated IP address. Continuous re‑scanning of the domain on multi‑engine services is advised to capture any escalation in detection rates. Organizations that handle credentials related to the implied brand should educate users about the recent domain appearance and reinforce MFA controls to mitigate potential credential theft. Ongoing threat‑intel feeds should be consulted for updates on blocklist status or additional detections. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260726-089E46 TLS cert SHA-256: 49e91f0b59b3ad8048e71321ea679897f4ac84f8fc8648aad2520e91d1afb898 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/830129coinbase.com/ JSON API: https://api.destroy.tools/v1/check?domain=830129coinbase.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 201,051 domains (87,732 alive under monitoring, 112,288 confirmed takedowns/dead). Site: https://phishdestroy.io