Analysis of coinbase-card.vip shows a high‑risk infrastructure consistent with a generic phishing operation. The domain resolves to IP address 186.2.175.35 and was registered on July 09, 2026 through Fewmoretaps OU d/b/a Trustname.com. Its authoritative name servers are ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, and zeus.trustname.com, indicating the use of a multi‑provider DNS setup that is often leveraged to increase resilience against takedown attempts.
The domain appears on three security blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL, confirming that multiple threat‑intelligence feeds have identified it as malicious. VirusTotal scans report that 22 of 91 security vendors flag the domain, reinforcing the suspicion of malicious activity. No public page title or content analysis is currently available, so the exact phishing lure or credential‑stealing page cannot be described.
Defenders should treat any traffic to coinbase-card.vip as hostile: block the domain at perimeter firewalls, proxy filters, and DNS resolvers; add the IP 186.2.175.35 to deny lists; monitor for any outbound connections to the listed nameservers; and ensure that endpoint security solutions are updated to include the latest vendor detections. Continuous monitoring of blocklist updates and VirusTotal re‑scans is recommended to capture any changes in the threat landscape associated with this domain.