# PhishDestroy threat dossier — coinbaseguardian.com ================================================================ Fetched: 2026-04-22 10:17:21 UTC Canonical: https://phishdestroy.io/domain/coinbaseguardian.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Coinbase ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/94 security vendors flagged this domain Flagging vendors: CyRadar URLQuery: 2 detections Public blocklists: listed on 2 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 88.222.222.243 (LT, Vilnius) ASN: AS47583 Hostinger International Limited Hosting org: Hostinger International Ltd. Registrar: HOSTINGER operations, UAB Nameservers: ["atlas.dns-parking.com", "hyperion.dns-parking.com"] Registered: 2026-04-16 Page title: Hostinger Horizons ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-07-14 Status: INVALID chain Fingerprint: dfd3548c6204490badab7f0ba0c76c11f96e1b658b0bb25945f0a9e6b2a0da05 Subject Alternative Names (related infrastructure — often same operator): - www.coinbaseguardian.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-16 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-16 18:04:57 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-04-16 15:06:03 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-04-22 09:39:52 UTC Neutralised: 2026-04-22 08:39:52 UTC Current status: taken down (registrar suspended or DNS dead) Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019d96d1-5307-755e-a5de-3f3979c7138d/ URLQuery: https://urlquery.net/report/1d80b3ce-f60f-4d21-b0e8-a787cca1f940 Wayback Machine: https://web.archive.org/web/*/coinbaseguardian.com crt.sh CT logs: https://crt.sh/?q=%25.coinbaseguardian.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=coinbaseguardian.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/coinbaseguardian.com URLhaus: https://urlhaus.abuse.ch/host/coinbaseguardian.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-16 18:07:02 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] coinbaseguardian.com has been identified as an active phishing domain impersonating Coinbase. The threat type is brand impersonation, which carries a high risk due to the likelihood of users unknowingly disclosing credentials or financial information to malicious actors. This domain was flagged by MetaMask and SEAL, and it currently appears on 2 security blocklists. PhishDestroy identifies this as a credible threat leveraging Coinbase’s brand for credential harvesting or cryptocurrency theft. This domain was flagged on April 15, 2026, and is registered through HOSTINGER operations, UAB. It resolves to IP 88.222.222.243 and holds an SSL certificate issued by Let's Encrypt. VirusTotal analysis shows 0/95 detections, indicating it has not yet been widely recognized as malicious by antivirus engines. The page title “Hostinger Horizons” suggests a possible hosting-related misdirection, while the impersonation of Coinbase implies a targeted phishing campaign aimed at cryptocurrency users. To mitigate exposure, avoid visiting coinbaseguardian.com or any subpages linked from emails, ads, or third-party sites. Do not enter credentials or financial details on this domain. Users who may have interacted with the site should immediately change their Coinbase account password, enable two-factor authentication, and scan local devices for malware. Report any suspicious activity to Coinbase support and consider revoking any recently shared API keys or seed phrases. Organizations should update threat intelligence feeds and firewall rules to block both the domain and its associated IP address. Stay vigilant for further impersonation campaigns targeting cryptocurrency platforms. [Updates since narrative was generated:] - VirusTotal detections: now 1/94 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260416-6A8AB6 Favicon MD5: 6b0c3a937095705c09335887d2269e9d TLS cert SHA-256: dfd3548c6204490badab7f0ba0c76c11f96e1b658b0bb25945f0a9e6b2a0da05 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/coinbaseguardian.com/ JSON API: https://api.destroy.tools/v1/check?domain=coinbaseguardian.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io