login-coinbase-pro[.]blogspot[.]cz
“Coinbase Pro Login | Sign In – Cryptocurrency Broker and Exchange”
login-coinbase-pro.blogspot.cz — Non vérifié. Usurpation de l'identité de la marque : Coinbase; Type d'arnaque : Crypto Scam. Résumé des preuves: VirusTotal 11/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLScan malicious verdict; PhishDestroy score 83/100. Bureau d’enregistrement: MarkMonitor.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis shows that login-coinbase-pro.blogspot.cz is an active brand‑impersonation infrastructure targeting Coinbase users. The domain, created on February 06, 2007, resolves to the IPv6 address 2a00:1450:4001:81c::2001, which belongs to AS15169 Google LLC and is hosted in Germany. DNS is served by Google’s authoritative name servers (ns1‑ns4.google.com). The site presents a TLS certificate issued by Google Trust Services/WE2, confirming the use of Google’s certificate infrastructure. HTTP requests receive a 302 redirect, and the page title returned is "Coinbase Pro Login | Sign In – Cryptocurrency Broker and Exchange," indicating an attempt to mimic Coinbase’s authentication portal. Detected technologies include Blogger, Java, Python, OpenGSE, and HTTP/3, consistent with a hosted blog platform repurposed for malicious use. The domain is listed on one security blocklist and has been flagged by 11 of 95 VirusTotal scanners, suggesting moderate detection confidence. Registration was performed through MarkMonitor, Inc., a registrar commonly used for legitimate brand domains, which may aid evasion. While the specific payload or credential‑harvesting mechanisms have not been publicly disclosed, the presence of a Coinbase‑related page title and classification as a crypto scam imply a credential‑stealing or fund‑diversion campaign. Defenders should block the domain at network perimeter and endpoint controls, monitor for DNS queries to login-coinbase-pro.blogspot.cz, and update intrusion‑detection signatures to capture the observed HTTP 302 response pattern. Users should be reminded that legitimate Coinbase login pages are served exclusively from official Coinbase domains and that any request to a blogspot.cz sub‑domain is malicious. Continuous intelligence gathering is advised to track any evolution of the site’s content or infrastructure.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 5 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif