rajput-coinbase[.]netlify[.]app
“Coinbase - Buy and Sell Bitcoin”
rajput-coinbase.netlify.app — Contenu indisponible. Usurpation de l'identité de la marque : Coinbase; Type d'arnaque : Crypto Scam. Résumé des preuves: VirusTotal 6/93 (ADMINUSLabs, Emsisoft, Google Safebrowsing, Kaspersky, Netcraft); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 68/100. Bureau d’enregistrement: Netlify.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, rajput-coinbase.netlify.app, was registered on February 25, 2026 through the Netlify hosting platform. The site presented the page title “Coinbase – Buy and Sell Bitcoin,” indicating an attempt to impersonate the Coinbase brand. DNS resolution points to the IPv4 address 18.208.88.157, which belongs to Amazon.com Inc. (AS16509) and is geolocated in Germany. The server responded with HTTP 404, and the SSL certificate in use is a DigiCert Global G2 TLS RSA SHA256 2020 CA1 certificate issued by DigiCert Inc., confirming a valid TLS chain but not mitigating the brand‑spoofing risk.
The infrastructure stack includes Netlify services and HTTP Strict Transport Security (HSTS), while authoritative nameservers are dns1.p01.nsone.net through dns4.p01.nsone.net. Threat intelligence sources have placed the domain on three security blocklists, and it is actively blocked by PhishDestroy, MetaMask, and SEAL. VirusTotal analysis shows that six of ninety‑three scanning engines flagged the domain as malicious, reinforcing the suspicion of a crypto‑scam campaign. The domain is currently offline, but its recent creation date and hosting on a popular static‑site provider suggest a low‑cost, quickly deployed impersonation kit.
Defenders should continue to monitor the IP address 18.208.88.157 for any future activity, add the domain to local blocklists, and enforce outbound filtering for URLs containing the “coinbase” keyword that resolve to Netlify‑hosted IP ranges. Email gateways should be configured to detect messages referencing the “Coinbase – Buy and Sell Bitcoin” title or similar subject lines. Given the confirmed brand impersonation and the presence on multiple blocklists, organizations handling cryptocurrency‑related traffic should treat any traffic from this domain as malicious until it is definitively removed from threat feeds.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 2 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com Confiance à 100 %HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confiance à 100 %Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif