coinbase-us[.]created[.]app
“Coinbase Extension - Secure Crypto Trading Browser Extension | Download Free”
Riepilogo delle prove
Analysis indicates that the domain coinbase-us.created.app was registered through Tucows Domains Inc. on July 12, 2023. The domain resolves to the IP address 216.150.1.193, which belongs to Amazon.com, Inc. (AS16509) and is geolocated in the United States. DNS resolution uses Vercel name servers (ns1.vercel-dns.com, ns2.vercel-dns.com), and the site was served over HTTPS with a Let’s Encrypt R13 certificate that includes HTTP Strict Transport Security. A request to the root URL returns HTTP status 404, and the page title presented by the server reads “Coinbase Extension - Secure Crypto Trading Browser Extension | Download Free”, explicitly referencing the Coinbase brand.
Google Safe Browsing classifies the URL as a social engineering threat, and ten of ninety‑five VirusTotal scanners have flagged the domain as malicious. The site has been added to a single security blocklist and is presently blocked by the PhishDestroy feed. The threat profile is labeled as a crypto‑related scam that impersonates Coinbase, aligning with the brand‑impersonation strategy observed in other cryptocurrency phishing campaigns. At the time of assessment the domain is offline, which limits current content analysis, but the combination of brand‑specific page title, SSL configuration, hosting on a major cloud provider, and multiple vendor detections provides sufficient evidence of malicious intent.
Defenders should continue to block the domain at perimeter and DNS layers, monitor the associated IP address for any future activation, and consider adding the URL to internal threat‑intelligence feeds. Ongoing observation of the hosting provider and registrar may reveal re‑use of the infrastructure for new campaigns. Until the site is taken down permanently, organizations should educate users about unsolicited requests to install browser extensions claiming to be from Coinbase.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 10/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Stato del dominio
Raggiungibile → Non raggiungibile
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ICANN OVERSIGHT
Registration: created.app
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain created.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie
2 tecnologie identificate con alta affidabilità
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo