coinbase-verify[.]xo[.]je
“coinbase-verify.xo.je”
coinbase-verify.xo.je — Non verificato. Simulazione del marchio: Coinbase; Tipo di truffa: Crypto Scam. Riepilogo delle prove: VirusTotal 20/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Certego); Spamhaus DBL_PHISH; PhishDestroy score 95/100.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
This domain, coinbase-verify.xo.je, is assessed as an elevated-risk credential harvesting phishing site specifically targeting Coinbase users. Analysis indicates the infrastructure was designed to deceive victims into submitting login credentials, two-factor authentication codes, or other sensitive account details under the guise of a legitimate verification process. The threat type aligns with brand impersonation, a tactic frequently employed to exploit trust in well-known financial platforms for unauthorized account access or fraudulent transactions. Infrastructure analysis reveals the domain was hosted on IP address 185.27.134.114, geolocated in the United Kingdom under AS34119 (Wildcard UK Limited). The domain currently appears on one security blocklist, while VirusTotal detection metrics report 20 out of 95 security vendors flagging the domain as malicious. No SSL certificate was present, increasing the likelihood of interception or manipulation of transmitted data. The page title, coinbase-verify.xo.je, directly mirrors the domain name, a common indicator of phishing sites attempting to reinforce perceived legitimacy. The registrar for the xo.je second-level domain is Njalla, a provider historically associated with anonymized or abuse-prone registrations. Mitigation against this specific threat involves immediate domain blacklisting at the network perimeter and endpoint levels. Organizations should ensure security controls block access to 185.27.134.114 and the xo.je domain, while also monitoring for internal connections to these indicators. Users who may have interacted with the site should be instructed to reset Coinbase credentials from a verified device, enable multi-factor authentication if not already active, and review account activity for unauthorized transactions. Security teams are advised to correlate logs for connections to the IP address or domain to identify potentially compromised endpoints. Proactive monitoring of newly registered domains under Njalla or similar registrars may help detect emerging threats before they reach end users.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
Analisi di VirusTotal
Prove archiviate
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo