coinbasecryptoblizt[.]digital
“Crypto Blizt”
Resumen de las pruebas
coinbasecryptoblizt.digital was observed resolving to the Amazon Web Services address 63.176.8.218 located in Germany (AS16509). The domain is registered through Name.com, Inc., and uses the DNS infrastructure of NS1 (dns1.p04.nsone.net through dns4.p04.nsone.net). A DigiCert Global G2 TLS RSA SHA256 2020 CA1 certificate is presented, indicating a valid TLS chain but offering no credibility for the content. The site returned HTTP 404, and the page title reported by scanners is “Crypto Blizt”, which aligns with the classified scam type “Crypto Scam”.
Google Safe Browsing flagged the domain for social engineering, and 13 of 95 VirusTotal scanners labeled it malicious, suggesting a consensus among security vendors that the site is used for credential or asset theft. The domain impersonates Coinbase, a high‑value financial brand, and is listed on at least one public blocklist, with PhishDestroy confirming its takedown. Current status is offline, but the infrastructure—particularly the AWS‑hosted IP and the NSOne name servers—remains reusable for future campaigns.
Uncertainty remains regarding the exact payload or phishing page content, as only the HTTP 404 response and title have been captured. Defenders should continue to block the domain and associated IP, monitor the NSOne name servers for new subdomains, and update detection rules to flag any future resolutions to 63.176.8.218 that reference Coinbase or cryptocurrency‑related keywords. Incident response teams should also consider hunting for artifacts of credential harvesting attempts that may have been directed at Coinbase users during the brief live window.
Data Coverage
Señales de seguridad
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Estado del dominio
Accesible → Inaccesible
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
-
Estado del dominio
Inaccesible → Accesible
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.