cqbiwapi[.]bip39[.]vip
“Coinbase - 购买和出售比特币、以太坊以及其他可靠币种”
Infrastructure analysis reveals cqbiwapi[.]bip39[.]vip is registered via Gname.com Pte. Ltd., created just 6 days ago. The domain was registered just 6 days ago, highly suspicious for any legitimate business. The resolved IP address is 188.114.97.3. The domain is listed on PhishDestroy, MetaMask, SEAL security blocklists.
This phishing domain has been taken down and is no longer accessible. PhishDestroy's reports contributed to the removal of cqbiwapi[.]bip39[.]vip, which is now offline. However, similar threats may appear under new domains.
PhishDestroy has identified similar threats: Other suspicious domains registered via Gname.com Pte. Ltd.: [j298k.xyz](/domain/j298k.xyz), [link.brawlstar.top](/domain/link.brawlstar.top).
Threat Response Pipeline
Public Blocklist Status
Evidence Capture
Domain Intelligence
grace.ns.cloudflare.com
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If you have interacted with this domain, entered personal information, or connected a cryptocurrency wallet — take immediate action. Below are resources to help you report the incident and protect yourself.
Report to Your Local Authorities
Select your country to see local cybercrime reporting contacts and complaint templates.
Related Domain Reports
Other Domains on 188.114.97.3
More Domains at Gname.com Pte. Ltd.
About This Report: cqbiwapi.bip39.vip
This domain security report for cqbiwapi.bip39.vip is maintained by PhishDestroy's automated threat intelligence pipeline. Our system continuously monitors this domain across 95 security vendors on VirusTotal, 3 public blocklists, URLScan.io.
The site displays a page titled “Coinbase - 购买和出售比特币、以太坊以及其他可靠币种”.
cqbiwapi.bip39.vip has been flagged by 10 security vendors as of February 28, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.
Stay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive



URLScan Report