coinbaseku[.]cc
“Coinbase”
Résumé des preuves
On July 23, 2026 analysts examined the domain coinbaseku.cc, which was taken offline after being identified as a crypto‑related brand‑impersonation site targeting Coinbase users. The domain was registered on August 31, 2025 through Gname.com Pte. Ltd. and resolves to the IPv4 address 205.198.94.130, hosted in Germany under ASN 138997 (Eons Data Communications Limited). The authoritative name servers are a5.share-dns.com and b5.share-dns.net. An SSL certificate issued to “Internet Widgits Pty Ltd” is present, which does not correspond to the legitimate Coinbase brand, further indicating malicious intent. The page title returned by the site is simply “Coinbase”, matching the advertised brand target.
Scamadviser assigned a trust score of 1 / 100, while Gridinsoft rated the domain 0 / 100, reflecting extreme suspicion. The domain appears on a single security blocklist and is explicitly blocked by PhishDestroy. VirusTotal analysis shows that 16 of 95 scanning engines flagged the domain as malicious, corroborating the low trust scores. No additional public threat‑intel sources such as OTX or Google Safe Browsing were referenced in the available data. The evidence points to a crypto‑scam infrastructure that likely attempted to harvest Coinbase credentials or lure victims into fraudulent transactions.
Because the site is currently offline, immediate mitigation focuses on updating detection rules: block the domain and its resolved IP, add the observed name servers to threat‑intel feeds, and incorporate the SSL subject and low trust scores into automated filters. Defenders should monitor for re‑registration of similar‑looking domains and for any new activity from the same hosting ASN. Continuous observation of the registrar Gname.com Pte. Ltd. for future abusive registrations is also advised.
Data Coverage
Signaux de sécurité
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 10/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
État du domaine
Accessible → Inaccessible
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
État du domaine
Inaccessible → Accessible
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif