coinbase--extension-set[.]pages[.]dev
Analyse phishing et sécurité de coinbase--extension-set.pages.dev
“Suspected phishing site | Cloudflare”
coinbase--extension-set.pages.dev — Accessible · accès restreint (HTTP 403). Usurpation de l'identité de la marque : Coinbase; Type d'arnaque : Crypto Scam. Résumé des preuves: VirusTotal 16/93 (ADMINUSLabs, ChainPatrol, Criminal IP, alphaMountain.ai, BitDefender); URLScan malicious verdict; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 100/100. Bureau d’enregistrement: Cloudflare.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, coinbase--extension-set.pages.dev, is a high-risk credential phishing site specifically designed to impersonate the Coinbase cryptocurrency exchange platform. The site targets users by mimicking the legitimate Coinbase interface, aiming to harvest login credentials, two-factor authentication codes, and sensitive financial information. Analysis indicates the domain was constructed to exploit trust in the Coinbase brand, leveraging realistic UI elements and deceptive URLs to trick victims into disclosing account access details. The threat extends beyond individual compromise, as stolen credentials can facilitate unauthorized transactions, account takeovers, and broader financial fraud schemes targeting the cryptocurrency ecosystem. Infrastructure analysis reveals multiple concrete indicators supporting the phishing classification. The domain was registered on October 8, 2025, through Cloudflare, Inc., and is flagged by 16 out of 95 security vendors on VirusTotal as malicious. It appears on one security blocklist and is explicitly blocked by PhishDestroy. The domain resolves to the IP address 172.66.47.137, hosted on Cloudflare's US-based network (AS13335), and uses an SSL certificate issued by Google Trust Services (WE1). Google Safe Browsing has also classified the domain as phishing, further corroborating its fraudulent nature. The page title, 'Suspected phishing site | Cloudflare,' suggests even the hosting provider's automated systems detected and flagged the malicious intent. Users who visited coinbase--extension-set.pages.dev or entered credentials on the site should take immediate remedial action. First, revoke any active sessions and change passwords for Coinbase and any other accounts where identical or similar credentials may have been reused. Enable multi-factor authentication using an authenticator app or hardware key, avoiding SMS-based methods due to susceptibility to interception. Monitor all linked financial accounts and cryptocurrency wallets for unauthorized transactions, and report any suspicious activity to the legitimate platform. If personal or financial information was disclosed, consider placing a fraud alert with credit bureaus and reviewing identity theft protection measures. The domain has since been taken offline, but users should remain vigilant for follow-up phishing attempts via email or messaging platforms.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confiance à 100 %Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of coinbase--extension-set.pages.dev · checked Mar 2, 2026
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif