cccoinbas[.]vip
Análisis de phishing y seguridad de cccoinbas.vip
“Coinbase”
cccoinbas.vip — Contenido no disponible (HTTP 502). Suplantación de marca: Coinbase; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 11/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker); Google Safe Browsing flagged; PhishDestroy score 83/100. Registrador: Domain International S….
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain cccoinbas.vip was created on November 27, 2025 and is registered through Domain International Services Limited. It is delegated to four nameservers (ns1.domainnamedns.com, ns2.domainnamedns.com, ns3.domainnamedns.com, ns4.domainname) and resolves to the IP address 202.95.15.49, which belongs to AS152194 owned by CTG Server Limited in Hong Kong. No SSL certificate is present, indicating that the site only served unsecured HTTP traffic when it was active. The page title returned by the site was "Coinbase", matching the declared brand target of Coinbase and confirming a brand‑impersonation intent.
Google Safe Browsing categorised the domain as "social engineering", and 11 of the 95 vendors on VirusTotal flagged it, reinforcing the malicious assessment. Gridinsoft assigned a trust score of 0 out of 100, and the domain appears on at least one public blocklist, with PhishDestroy explicitly blocking it. The operational status is currently offline, so direct content inspection is not possible; consequently, response codes, exact page markup, and any credential‑harvesting forms remain unknown.
Defenders should continue to block the domain and its resolved IP, add the domain to internal deny lists, and monitor for any re‑registration attempts. Updating IDS/IPS signatures with the observed hostnames, nameserver pattern, and the association to the HK hosting AS can help detect future campaigns that reuse similar infrastructure. Monitoring for other domains that resolve to 202.95.15.49 or share the same registrar may uncover related phishing infrastructure targeting cryptocurrency users.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Inteligencia forense
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.