conbase-authenticated-appdashboardweb[.]duia[.]ro
“Coinbase - Sign In”
Resumen de las pruebas
The domain conbase-authenticated-appdashboardweb.duia.ro is flagged as a Coinbase impersonation used for a crypto‑scam operation. Registration records show the domain was created on 31 August 2011 and is listed under the registrar CYBER_FOLKS S.R.L., indicating a long‑standing registration that predates the recent activity. The authoritative name servers are ns1.duiadns.net and ns2.duiadns.net, both associated with the duia.ro zone. Network analysis reveals the domain resolves to the IPv4 address 130.94.12.172, which belongs to AS154177 (LIGHT NODE LIMITED) and is geolocated in the United States. No TLS certificate is presented; the site is served over plain HTTP, a typical characteristic of fraudulent credential‑harvesting pages. The page title returned by the web server is “Coinbase – Sign In”, directly mirroring the legitimate brand’s login portal.
Reputation services provide strong evidence of malicious intent. The domain appears on a single security blocklist, where it is listed by PhishDestroy. Gridinsoft assigns a trust score of 0 out of 100, the lowest possible rating. VirusTotal reports that 14 of 93 scanners flag the domain as malicious, reinforcing the suspicion. The overall classification from the supplied intelligence is a “Crypto Scam”, confirming that the site is likely intended to capture cryptocurrency‑related credentials or to lure victims into fraudulent transactions. The current operational status is offline, which may be a temporary takedown or a shift to a different hosting location.
Defenders should continue to block the domain at perimeter firewalls, DNS filters, and proxy devices. Because the domain resolves to an IP owned by a public cloud provider, additional monitoring of the IP address for any future re‑use is advisable. Threat‑intel feeds that incorporate the registrar, name‑server, and ASN information can be enriched to catch any new domains created by the same entity.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 13/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.