coinbaseexchang[.]webflow[.]io
“404 - Page not found”
Résumé des preuves
Analysis of coinbaseexchang.webflow.io indicates a high‑risk brand‑impersonation campaign targeting Coinbase users. The domain resolves to 172.64.151.8, an address owned by AS13335 Cloudflare, Inc. and is served through Cloudflare’s network using HTTP/3. Both authoritative nameservers, journey.ns.cloudflare.com and lamar.ns.cloudflare.com, are Cloudflare‑controlled, confirming the hosting provider. The TLS certificate presented is issued by Google Trust Services under the WE1 root, which is typical for Cloudflare‑proxied sites and does not, by itself, indicate malicious intent. A HTTP request to the domain returns a 404 status with the page title "404 - Page not found," and the site is currently listed as offline.
Google Safe Browsing flags the domain for social engineering, and the domain appears on one external security blocklist and is blocked by PhishDestroy. VirusTotal records 15 of 95 scanning engines flagging the domain, reinforcing the suspicion of malicious activity. The registrar is MarkMonitor, Inc., and the domain was originally created on May 08, 2013. Scamadviser assigns a trust score of 1 out of 100, reflecting extreme distrust.
The intelligence explicitly labels the operation as a crypto‑scam that impersonates Coinbase, but no further content analysis is available because the site returns only a generic 404 page. Uncertainty remains regarding any active payload, phishing pages, or credential‑harvesting forms, as no live content could be examined. Defenders should treat the domain as malicious: add the domain and its resolving IP to web‑filter deny lists, monitor DNS queries for related subdomains, and enforce outbound traffic controls that block connections to Cloudflare‑hosted IPs associated with this identifier. Continuous re‑evaluation is advised in case the infrastructure is re‑activated or new content is observed.
Data Coverage
Signaux de sécurité
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
État du domaine
Accessible → Inaccessible
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif