# PhishDestroy threat dossier — coinbasecoin.top ================================================================ Fetched: 2026-06-30 16:34:17 UTC Canonical: https://phishdestroy.io/domain/coinbasecoin.top/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 86/100 (PhishDestroy scoring — see methodology below) Targeted brand: Coinbase ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 13/91 security vendors flagged this domain Flagging vendors: ADMINUSLabs, ChainPatrol, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET, G-Data, Gridinsoft, Lionic, Sophos, Webroot Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 185.199.108.153 (US, San Francisco) ASN: ASAS54113 FASTLY - Fastly, Inc., US Hosting org: AS54113 Fastly, Inc. Registrar: NameSilo, LLC !!! REGISTRAR INTEGRITY ALERT — NameSilo !!! NameSilo is a registrar documented by PhishDestroy as (1) publicly lying about received abuse reports, (2) shielding a $20M+ Monero-theft operation (xmrwallet.com) for 10 continuous years, and (3) retaliating against PhishDestroy by getting our X/Twitter account @Phish_Destroy banned after we published the evidence. Researchers/victims must ALWAYS CC compliance@icann.org on every abuse ticket — NameSilo has a track record of later claiming reports were never received. Primary sources: https://phishdestroy.io/namesilo-killed-our-twitter https://phishdestroy.io/xmrwallet-namesilo-exposed Nameservers: ns1.dnsowl.com, ns2.dnsowl.com, ns3.dnsowl.com Registered: 2025-06-25 Expires: 2027-06-25 Page title: Wrapped Coinbase - Tokenized Assets HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-26 Status: INVALID chain Fingerprint: dc4b1beeeb0e2b61e7a4aca903ae32dc9f9de7a13d3dc3a854510ce01b175cd3 Subject Alternative Names (related infrastructure — often same operator): - www.coinbasecoin.top ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-06-25 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-28 23:08:56 UTC (by PhishDestroy tracker) First reported: 2026-06-28 21:12:33 UTC (abuse notice filed) Last verified: 2026-06-30 16:20:34 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f100f-8ed8-7338-a60a-9414f03e35cd/ URLQuery: https://urlquery.net/report/1bdd4c67-45e1-447d-a14e-b0e96bb2c36e Wayback Machine: https://web.archive.org/web/*/coinbasecoin.top crt.sh CT logs: https://crt.sh/?q=%25.coinbasecoin.top Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=coinbasecoin.top AlienVault OTX: https://otx.alienvault.com/indicator/domain/coinbasecoin.top URLhaus: https://urlhaus.abuse.ch/host/coinbasecoin.top/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-28 23:14:39 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] This domain, coinbasecoin.top, is classified as a brand impersonation threat specifically targeting the Coinbase cryptocurrency exchange platform. The domain name mimics the legitimate Coinbase brand by appending 'coin' and using a .top TLD, a common tactic in phishing campaigns. No specific drainer kit has been identified, but the domain is actively used to deceive users into divulging credentials or sensitive information. Technical indicators confirm a high risk level. VirusTotal reports 13 out of 95 security vendors flagging this domain as malicious. The domain was registered through NameSilo, LLC on June 25, 2025, and resolves to IP address 185.199.108.153. An active SSL certificate from Let's Encrypt is present, which lends a false sense of legitimacy. Google Safe Browsing status is not provided, but the domain remains active and unblocked. Current status shows the domain is still active and operational. Recommended response actions include blocking the domain at network perimeter, adding it to threat intelligence feeds, and conducting user awareness training to prevent credential theft. Remaining risk is high due to the active SSL certificate and recent creation date, which may evade some security controls. Users should verify URLs carefully and avoid entering credentials on this domain. [Updates since narrative was generated:] - WHOIS creation date: 2025-06-25 ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260628-F12B33 Favicon MD5: a2a411ba113308850859f9be2ecb71d2 TLS cert SHA-256: dc4b1beeeb0e2b61e7a4aca903ae32dc9f9de7a13d3dc3a854510ce01b175cd3 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/coinbasecoin.top/ JSON API: https://api.destroy.tools/v1/check?domain=coinbasecoin.top Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 172,677 domains (12,855 alive under monitoring, 159,232 confirmed takedowns/dead). Site: https://phishdestroy.io