koinbaseproologg.webflow.io
“ÇOINɃAS𝔢 PRO LOGIN $ DIGITAĹ ASSET EXĈHAŅGE”
Evidence Summary
PhishDestroy identifies a high-risk phishing domain, koinbaseproologg.webflow.io, designed to impersonate KoinBase Pro. This domain employs a generic phishing tactic primarily targeting users of cryptocurrency exchange platforms. The threat actor replicates the official KoinBase Pro interface to deceive victims into entering their login credentials or transferring digital assets. The campaign relies on urgency and social engineering to trick users into authorizing fraudulent transactions. No specific drainer kit has been linked to this domain as of the latest analysis.
This domain exhibits multiple red flags confirmed by technical indicators. The domain resolves to IP address 172.64.151.8 and is flagged by 18 out of 95 security vendors on VirusTotal, reflecting considerable malicious activity. It also holds a Google Trust Services SSL certificate, increasing its appearance of legitimacy. Google Safe Browsing categorizes this domain under social engineering, and it is blocked by industry-leading security systems such as SEAL and MetaMask. Additionally, the domain appears on two security blocklists. These combined indicators suggest this domain is actively involved in fraudulent activities.
The status of koinbaseproologg.webflow.io remains active, posing an ongoing threat to unsuspecting users. Security vendors and platforms have taken immediate action by blocking and flagging the domain, limiting its operational capacity. Despite these efforts, the domain persists, and the remaining risk remains high due to its ability to evade detection through trusted domains such as webflow.io. Users are strongly advised to verify website URLs carefully, avoid entering sensitive information, and report suspicious domains to their respective security teams or browser vendors. Remaining vigilant and using multi-factor authentication can significantly reduce exposure to this and similar threats.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | koinbaseproologg.webflow.io |
malicious | Sinkholed |
| OpenDNS | koinbaseproologg.webflow.io |
phishing | Phishing Block |
| Quad9 DNS | koinbaseproologg.webflow.io |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Stored observation
Observed title contrast
Technologies · 3 identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of koinbaseproologg.webflow.io · checked Apr 24, 2026
Community reports
Reported by 1 community member, first seen Apr 24, 2026
- Stored reports
- 1
- Unique reported URLs
- 1
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive