MALICIOUS — CRITICAL
securityalert-coinbase[.]com
The domain securityalert-coinbase.com was registered on November 24, 2025 through NiceNIC International Group Co., Limited and is currently taken offline.
- VirusTotal
- 8/91
- Blocklists
- No stored match
- उपलब्धता
- सामग्री अनुपलब्ध · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
securityalert-coinbase.com — सामग्री अनुपलब्ध (HTTP 502). ब्रांड प्रतिरूपण: Coinbase; घोटाले का प्रकार: Crypto Scam. साक्ष्य सारांश: VirusTotal 8/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, Chong Lua Dao, Forcepoint ThreatSeeker); Spamhaus DBL_PHISH; PhishDestroy score 74/100. रजिस्ट्रार: NiceNIC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Evidence Analysis
The domain securityalert-coinbase.com was registered on November 24, 2025 through NiceNIC International Group Co., Limited and is currently taken offline. DNS resolution points to the IPv4 address 45.137.99.102, which belongs to AS214209 operated by Internet Magnate (Pty) Ltd and geolocates to Romania. The authoritative name servers are demi.ns.cloudflare.com and lennox.ns.cloudflare.com, indicating use of Cloudflare’s DNS service. No TLS certificate is presented for the host, and the site served without HTTPS.
A scan on VirusTotal returned eight positive detections out of ninety‑five vendors, confirming malicious activity. Gridinsoft assigned a trust score of zero out of one hundred, and the domain appears on a single external blocklist. PhishDestroy has already blocked the domain, and it is listed as a crypto‑related scam targeting the Coinbase brand. The page title returned by HTTP requests is "MagnusBilling", which does not correspond to the advertised brand and suggests a generic billing‑kit front‑end.
While the exact content of the site has not been captured, the combination of brand impersonation, lack of encryption, low trust score, and multiple vendor detections indicates a high likelihood of credential‑harvesting or crypto‑drain activity. Defenders should add the domain and its resolving IP to network deny lists, monitor for any resurgence of the host, and enforce strict outbound filtering for requests to unknown Cloudflare‑hosted domains. Continuous observation of the associated IP range and periodic re‑scanning are advised to catch potential re‑hosting attempts.
डेटा कवरेज12 recorded checks
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 02:11:53 UTC
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टेंIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।