MALICIOUS — CRITICAL
coinbas[.]pl
coinbas.pl is a newly registered domain, created on May 23 2026, that resolves to the IPv4 address 185.253.212.22.
- VirusTotal
- 6/91
- Blocklists
- 2 · MetaMask, SEAL
- उपलब्धता
- अंतिम ज्ञात सक्रिय · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
coinbas.pl — अंतिम ज्ञात सक्रिय (HTTP 200). ब्रांड प्रतिरूपण: Coinbase; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 6/91 (ChainPatrol, alphaMountain.ai); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 90/100. रजिस्ट्रार: Aftermarket.pl.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Evidence Analysis
coinbas.pl is a newly registered domain, created on May 23 2026, that resolves to the IPv4 address 185.253.212.22. An HTTP GET returns status code 200, indicating a responsive web server. The site presents a TLS certificate issued by a public certificate authority, typical of short‑lived phishing sites. Automated reputation scoring assigns a trust score of 0 out of 100, reflecting a highly malicious profile.
The domain is hosted under the Aftermarket.pl Limited registrar and uses the authoritative name servers ns1.aftermarket.pl and ns2.aftermarket.pl. Its mail exchanger points to blackhole.aftermarket.pl with priority 10, a configuration commonly employed to discard inbound mail. Geolocation of the IP places the host in Poland, linked to Michau Enterprises Limited, a provider previously observed in malicious infrastructure.
Threat intelligence sources flag coinbas.pl as high‑risk. The domain appears on three independent security blocklists and is referenced in one open‑source intelligence pulse. Multiple scanning engines label the host as malicious in six out of ninety‑five analyses. The overall risk rating is high and the domain status remains active.
Defenders should treat any traffic to or from coinbas.pl as hostile. Network perimeter controls ought to block outbound HTTP/HTTPS connections to the IP 185.253.212.22 and DNS resolution of the domain. Email gateways must reject messages that reference the MX host blackhole.aftermarket.pl. Continuous monitoring of the associated IP range and rapid updating of internal blocklists are advised to mitigate potential credential harvesting attempts.
डेटा कवरेज12 recorded checks
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टेंIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।