MALICIOUS — CRITICAL
cbhep-coinbase[.]com
The domain cbhep-coinbase.com is assessed as a high-risk brand impersonation threat.
- VirusTotal
- 11/93
- Blocklists
- No stored match
- Disponibilità
- Contenuto non disponibile · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
cbhep-coinbase.com — Contenuto non disponibile (HTTP 502). Simulazione del marchio: Coinbase; Tipo di truffa: Crypto Scam. Riepilogo delle prove: VirusTotal 11/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, CRDF, CyRadar); Spamhaus DBL_PHISH; PhishDestroy score 95/100. Registrar: NiceNIC.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
The domain cbhep-coinbase.com is assessed as a high-risk brand impersonation threat. It specifically targets users of the cryptocurrency exchange Coinbase, aiming to deceive individuals into divulging sensitive information or performing unauthorized transactions.
Analysis indicates that this domain is currently offline and was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. The domain resolves to the IP address 91.92.241.15 and was created on January 08, 2026. According to VirusTotal, 11 out of 95 security vendors have flagged this domain as malicious. Additionally, the domain appears on three security blocklists, further underscoring its potential threat. The SSL certificate is identified as R13, which may have been used to create a false sense of security among users. The trust score of this domain is low, as evidenced by the multiple flags and blocklists.
To mitigate the risks associated with this domain, users are advised to exercise caution when interacting with any URLs or emails that appear to be from Coinbase but lead to cbhep-coinbase.com. Organizations should update their security policies to include this domain in blocklists and train users to recognize and report such impersonation attempts. Implementing DNS-based filtering and using multi-factor authentication can also significantly reduce the likelihood of successful phishing attacks. Regularly monitoring for similar domain registrations and taking swift action to report and block them is crucial in protecting against brand impersonation threats.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete Registrar context
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 03:47:52 UTC
Informazioni forensi
Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.