coinward[.]net
“Coin ward”
Evidence Summary
The domain coinward.net is currently classified as a generic phishing site with an elevated risk rating and remains active as of the report date, August 04, 2026. Intelligence sources indicate that the domain appears on three independent security blocklists, demonstrating that it has been identified and flagged by multiple threat‑intelligence aggregators. A VirusTotal analysis shows that five of ninety‑one scanned security vendors have generated detections for the domain, confirming that at least a subset of reputable scanning engines recognize malicious activity associated with the host.
In addition, the domain is explicitly blocked by three commercial protection services: PhishDestroy, MetaMask, and SEAL, each of which has incorporated coinward.net into its deny‑list to protect end users from credential‑stealing attempts. The combination of multi‑list blocklist presence, partial vendor detections, and active blocking by specialized anti‑phishing products suggests a concerted phishing campaign rather than an isolated or false‑positive incident. While the available data does not disclose the underlying hosting infrastructure, registrar details, or SSL certificate characteristics, the existing evidence is sufficient to warrant immediate defensive actions.
Network defenders should ensure that coinward.net is added to local and cloud‑based deny lists, update intrusion‑prevention signatures, and monitor outbound traffic for any connections to the domain. Email security gateways should be configured to quarantine messages that reference coinward.net or contain URLs pointing to the host. Continuous re‑evaluation is advised, as additional attributes such as hosting IPs or page content may emerge in future analyses, potentially refining the threat profile and response posture.
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 13, 2026
8 monitored external feeds No match
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
10 high-confidence technologies identified
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive