site-pro-logn-protl[.]daftpage[.]com
“Coinbase Pro login Portal: Fast and Secure Access”
This domain, site-pro-logn-protl.daftpage.com, is currently active and resolves to IP 216.150.16.65, hosted on Amazon AS16509 in the United States. Registration was performed through OVH, SAS on 2021-10-24. The site presents the page title “Coinbase Pro login Portal: Fast and Secure Access,” indicating a brand-impersonation attempt targeting Coinbase. Infrastructure analysis shows the site is served via Vercel with DNS records ns1.vercel-dns.com and ns2.vercel-dns.com, uses a Let’s Encrypt R13 TLS certificate, and returns HTTP 308 redirects. Detected technologies include Node.js, React, Next.js, YouTube embeds, HSTS enforcement, Google Analytics, and Crisp live‑chat widgets. Security telemetry reports 10 of 95 VirusTotal scanners flagging the domain and its inclusion on one external blocklist; Gridinsoft assigns a trust score of 0/100 and PhishDestroy has blocked it. The observed kit is classified as a seed‑phrase phishing module, consistent with the crypto‑scam classification. While the page content has not been inspected, the combination of brand‑specific page title, credential‑stealing kit, and low trust scores strongly suggests malicious intent. Defenders should block the domain at the network perimeter, update URL filtering lists, and monitor for related command‑and‑control activity. Additional investigation of inbound traffic to 216.150.16.65 is recommended to identify potential victim interactions.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Registration: daftpage.com
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain daftpage.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 9 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
Cloud platform for frontend deployment, optimized for Next.js.
JavaScript library for building user interfaces with component-based architecture.
React framework for production with hybrid static and server rendering.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web analytics service tracking website traffic and user behavior.
marketingplatform.google.comModule bundler for modern JavaScript applications.
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of site-pro-logn-protl.daftpage.com · checked Mar 24, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive