welcome-coinpro-base[.]created[.]app
“Official Site | Coinbase Pro | Secure Your Crypto”
welcome-coinpro-base.created.app — Contenido no disponible. Suplantación de marca: Coinbase; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 7/95 (ChainPatrol, alphaMountain.ai, CyRadar, ESET, Lionic); Spamhaus DBL_PHISH; PhishDestroy score 71/100. Registrador: Tucows.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of welcome-coinpro-base.created.app shows that the domain was registered on July 12, 2023 through Tucows Domains Inc. and is currently hosted on Amazon's AS16509 network, resolving to 216.150.1.1. The authoritative name servers are ns1.vercel-dns.com and ns2.vercel-dns.com, indicating deployment on the Vercel platform. The site presented a TLS certificate issued by Let’s Encrypt (R13) and advertised HTTP Strict Transport Security (HSTS). An HTTP request returned a 404 status code, and the page title observed was “Official Site | Coinbase Pro | Secure Your Crypto,” directly referencing Coinbase and matching the declared brand target. The intelligence categorises the activity as a crypto‑related brand impersonation, with the scam type listed as “Crypto Scam.” VirusTotal scanned the domain and recorded detections by 7 of 95 security vendors, confirming malicious labeling by multiple engines.
PhishDestroy has already taken the domain offline, and it appears on one external blocklist. The domain is also flagged by the PhishDestroy blocklist and by at least one additional security blocklist. The observed indicators demonstrate a clear attempt to deceive users seeking Coinbase Pro services, leveraging a legitimate‑looking TLS certificate and the Vercel hosting environment to increase perceived trust. While the HTTP response is a 404, the presence of the targeted page title suggests that the content was previously served before takedown.
No additional payload, redirect chain, or credential‑harvesting page has been captured, leaving the exact user‑facing behavior uncertain. Defenders should continue to block the domain at DNS and proxy layers, monitor the associated IP address 216.150.1.1 for any future reuse, and update URL filtering rules to include the full domain name. Analysts should also flag any future registrations that reuse the same registrar, name‑server pair, or hosting provider in conjunction with Coinbase‑related keywords.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Registration: created.app
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain created.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 2 identified
Vercel is a cloud platform for static frontends and serverless functions.
vercel.com 100 % de confianzaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % de confianzaAnálisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.