Analysis of coinestra.net indicates that the domain is currently active and associated with a generic phishing campaign. The domain was registered through Dynadot Inc on June 05, 2026 and resolves to the IP address 172.67.137.45, which is hosted on Cloudflare infrastructure as evidenced by the authoritative nameservers aspen.ns.cloudflare.com and jimmy.ns.cloudflare.com. VirusTotal records show that 1 of 91 security vendors has flagged the domain, suggesting at least one detection of malicious activity.
The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy service, reinforcing the assessment of phishing intent. No additional intelligence such as Safe Browsing status, Open Threat Exchange indicators, SSL certificate details, or HTTP response codes is available at this time, leaving the content and exact phishing vector unverified.
Defenders should treat coinestra.net as high‑risk: enforce network‑level blocking, add the domain to internal threat feeds, monitor DNS queries for the associated IP, and consider sinkholing the domain to disrupt further activity. Continuous re‑evaluation is advised as additional detection data or content analysis becomes available.