Analysis of 19203910-coinbase.com indicates a high-risk phishing domain targeting Coinbase users, registered on July 30, 2026. The domain is currently active and resolves to IP address 162.159.140.166, hosted on Cloudflare infrastructure with nameservers braden.ns.cloudflare.com and love.ns.cloudflare.com. Google Safe Browsing has flagged the domain for social engineering, and it appears on one security blocklist, including PhishDestroy. The domain was registered through Cloudflare, Inc., a common registrar for both legitimate and malicious sites.
VirusTotal scans by 91 vendors show no detections as of the latest check, though this absence does not confirm safety or malicious intent. Infrastructure analysis reveals the domain uses Cloudflare hosting, which may obscure origin server details and complicate takedown efforts. The rapid registration-to-active status suggests urgency in deployment, a pattern consistent with phishing campaigns. Defenders should treat this domain as malicious based on Safe Browsing classification and blocklist inclusion.
No specific phishing kit or page content analysis is available at this time, but the domain name structure strongly implies an attempt to impersonate Coinbase. Organizations should block the domain at DNS and proxy levels, monitor for related subdomains or IP associations, and alert users to avoid interaction. Further investigation into SSL certificates, HTTP headers, and historical DNS records may provide additional context, though current evidence supports immediate mitigation.