cbmoa-coinbase[.]com
“Checking Connection - Please Wait”
cbmoa-coinbase.com — सामग्री अनुपलब्ध (HTTP 502). ब्रांड प्रतिरूपण: Coinbase; घोटाले का प्रकार: Crypto Scam. साक्ष्य सारांश: VirusTotal 10/93 (ChainPatrol, alphaMountain.ai, CRDF, CyRadar, Fortinet); URLQuery 2 alerts; Spamhaus DBL_PHISH; PhishDestroy score 80/100. रजिस्ट्रार: NiceNIC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Analysis of cbmoa-coinbase.com shows a high‑risk brand‑impersonation campaign targeting Coinbase users. The domain was registered through NiceNIC International Group Co., Limited and created on February 21, 2026. Infrastructure details reveal that the domain resolves to IP address 91.92.241.15, which is hosted in the Netherlands and assigned to AS202412 (Omegatech LTD). No SSL certificate is present, indicating that the site was delivered over plain HTTP. The page title returned by the server is "Checking Connection - Please Wait," which aligns with typical redirection or loading tactics used in credential‑harvesting flows.
Reputation services flag the domain heavily: Gridinsoft assigns a trust score of 0 / 100, and the domain appears on three security blocklists. It is actively blocked by PhishDestroy, MetaMask, and SEAL. VirusTotal analysis records 10 of 93 security vendors marking the domain as malicious, reinforcing the suspicion of a crypto‑related scam. The listed scam type is "Crypto Scam" and the campaign explicitly impersonates Coinbase, a high‑value financial brand.
Current operational status is offline, but the observed indicators suggest that the infrastructure may be reused for future campaigns. Defenders should ensure that DNS queries for cbmoa-coinbase.com are denied, add the associated IP 91.92.241.15 to network‑level blocklists, and monitor for any resurgence of the domain or similar virtualine.org name‑server patterns. Updating endpoint and web‑gateway filters with the observed blocklist entries and the low Gridinsoft score will reduce exposure. Continuous threat‑intel feeds should be consulted for any new detections linked to the same registrar, nameservers, or hosting ASN, as these components have historically been reused in brand‑impersonation operations.
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 03:47:52 UTC
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
PD-20260119-D61DCC Recipient: abuse@nicenic.net क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।