web-ext-coin-pro[.]pages[.]dev
“Coinbase Chrome Extension - Secure Crypto Access™”
Pengamatan tersimpan
Perbedaan judul yang diamati
Ringkasan bukti
PhishDestroy identifies the active domain web-ext-coin-pro.pages.dev as a generic phishing host designed to harvest Web3 wallet credentials under the guise of a bogus browser extension. The page mimics legitimate crypto tools, luring victims with promises of enhanced functionality while secretly exfiltrating private keys and seed phrases. Evidence suggests a drainer kit is in use, though the exact payload remains under analysis. This campaign targets users searching for Chrome or Firefox extensions that interact with blockchain networks, with traffic likely driven by SEO poisoning and paid ads pointing to the Cloudflare Pages subdomain. The threat is categorized as credential theft with potential fund loss once wallets are compromised.
Technical indicators confirm the following: the domain resolves to IP 172.66.47.50, is registered through Cloudflare, Inc., and secured with a Google Trust Services SSL certificate. VirusTotal currently shows 1/95 detections, indicating it remains undetected by most antivirus engines. The domain is served from Cloudflare Pages, a platform often abused by threat actors for rapid deployment and bulletproof hosting. Although the creation date is not publicly available due to Cloudflare’s privacy protections, the active status and zero detections imply recent deployment. Google Safe Browsing (GSB) has not yet flagged the domain, and no public blocklists currently include it. These factors contribute to a high dwell time, increasing the risk of successful victim engagement.
The domain remains active and under investigation, with the current risk level classified as 'under_investigation.' PhishDestroy continues to monitor the host via behavioral analysis and sandbox detonation to identify new payloads or infrastructure pivots. Users are advised to avoid visiting web-ext-coin-pro.pages.dev or any related links offering 'crypto extensions.' Validate browser add-ons exclusively through official stores and verify developer credentials. Organizations should implement DNS filtering rules to block the IP 172.66.47.50 and monitor internal endpoints for outbound connections to this domain. Remaining risk is assessed as elevated due to the lack of detection coverage and ongoing operational status.
Data Coverage
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Cakupan daftar blokir
10 sumber eksternal dipantau · snapshot tersimpan 10/08/2026
8 sumber eksternal dipantau Tidak cocok
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of web-ext-coin-pro.pages.dev · checked Apr 13, 2026
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive