sso-coinbasepro-cdn-e--auth[.]webflow[.]io
“Official Site® | Coinbase Pro | Digital Asset Exchange®”
sso-coinbasepro-cdn-e--auth.webflow.io — Contenido no disponible. Suplantación de marca: Coinbase; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 13/95 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 89/100. Registrador: MarkMonitor.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, sso-coinbasepro-cdn-e--auth.webflow.io, is hosted on a Cloudflare edge server (IP 172.64.151.8, AS13335, United States) and serves an HTTP/3 endpoint that currently returns a 404 status code. The site presents the page title “Official Site® | Coinbase Pro | Digital Asset Exchange®”, indicating a direct attempt to masquerade as Coinbase’s professional trading platform. Registration data shows the domain was created on 08 May 2013 and is listed with the registrar MarkMonitor, Inc., a service commonly used by legitimate enterprises. The TLS certificate is issued by Google Trust Services under the WE1 authority, and the authoritative nameservers are journey.ns.cloudflare.com and lamar.ns.cloudflare.com, both consistent with the Cloudflare hosting profile.
VirusTotal analysis has recorded 13 of 95 security scanners flagging the domain as malicious, and the domain appears on a single public blocklist. Independent threat‑intelligence feed PhishDestroy has also taken the domain offline, confirming that active hosting has been terminated. No additional public evidence such as screenshot archives or sandbox reports is available, so the precise malicious payload or credential‑harvesting mechanism remains unconfirmed. Defenders should add the fully qualified domain name to URL filtering and DNS‑sinkhole policies, especially any rules that target Coinbase‑related traffic.
Because the domain resolves to a Cloudflare‑owned IP, network‑level blocking should be applied to the specific IP address 172.64.151.8 only if it is known to be associated with this campaign, to avoid over‑blocking legitimate Cloudflare services. Continuous monitoring of the domain’s registrar (MarkMonitor) and its SSL fingerprint (Google Trust Services/WE1) can provide early indicators of re‑use. Threat‑intel teams should also watch for new sub‑domains that reuse the same naming pattern or reference the same page title, and update detection signatures accordingly.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % de confianzaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % de confianzaAnálisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.