coimbaseprollogin[.]webflow[.]io
“Coinbase Pro | Digital Asset Exchange”
Observation enregistrée
Contraste de titres observé
Résumé des preuves
This domain is classified as a high-risk credential harvesting site targeting users of the Coinbase Pro digital asset exchange platform. Analysis indicates the domain coimbaseprollogin.webflow.io is designed to impersonate the legitimate Coinbase Pro login interface, tricking victims into submitting sensitive authentication details such as usernames, passwords, and potentially two-factor authentication codes. The specific threat posed involves the unauthorized access to cryptocurrency exchange accounts, leading to financial theft and account takeovers. Infrastructure analysis reveals the following technical indicators: the domain resolves to IP address 172.64.151.8, hosted on Cloudflare infrastructure (AS13335) in the United States. The domain was originally created on May 08, 2013, though the malicious subdomain was likely deployed recently. VirusTotal detection shows 19 out of 95 security vendors flagging the domain as malicious. The domain appears on two security blocklists: PhishDestroy and PhishingDB. Google Safe Browsing has also classified this domain as a phishing site. The SSL certificate is issued by Google Trust Services (WE1), and the domain is registered through MarkMonitor, Inc., a registrar commonly used for both legitimate and malicious domains. Mitigation steps for this specific threat type include immediate blocking of the domain and its associated IP address (172.64.151.8) at the network perimeter. Security teams should deploy indicators of compromise (IOCs) into endpoint detection and response systems to prevent access. Users who may have interacted with this domain should be instructed to reset their Coinbase Pro credentials immediately, enable multi-factor authentication if not already active, and monitor their accounts for unauthorized transactions. Organizations should also conduct a retrospective analysis of network logs to identify any prior connections to this domain or IP address, ensuring no successful credential harvesting occurred.
Data Coverage
Signaux de sécurité
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
État du domaine
Accessible → Inaccessible
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Technologies
2 technologies identifiées avec une forte confiance
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif