Analysis as of August 01, 2026 indicates that the domain coinbase-invest--camrongraves4.replit.app is actively used in a high‑risk phishing campaign. The domain is registered through Replit Inc., and its A record resolves to the IPv4 address 34.117.33.233. No nameserver records were returned during lookup, which may reflect misconfiguration or deliberate obscuring of the authoritative servers. The domain appears on four reputable security blocklists and has been listed by PhishDestroy, MetaMask, OpenPhish, and SEAL, confirming its classification as malicious.
VirusTotal reports that 14 of 91 scanned security vendors have flagged the domain, providing independent confirmation of its malicious nature. Despite these indicators, the site remains reachable, and its current HTTP response, TLS certificate details, and page title have not been disclosed in the available intelligence, leaving the exact content and phishing vector unverified. Defenders should treat the domain as high‑severity infrastructure. Immediate mitigation steps include adding the domain and its resolved IP address to network deny lists, configuring DNS filtering to block any resolution attempts, and updating intrusion detection signatures to flag outbound traffic toward 34.117.33.233.
Continuous monitoring of Replit‑hosted subdomains is recommended, as the registrar has been used for other malicious deployments. Because the nameserver information is absent, threat hunters should query passive DNS archives for historical records that might reveal additional infrastructure ties. Lastly, security teams should share the indicator set with threat‑intel platforms to ensure broader community awareness.