commerce[.]infopayments-coinbase[.]com
“commerce.infopayments-coinbase.com”
Riepilogo delle prove
Analysis of commerce.infopayments-coinbase.com indicates a high‑risk brand‑impersonation campaign aimed at Coinbase users. The domain was registered on 2 May 2025 through PDR Ltd. d/b/a PublicDomainRegistry.com and resolves to the IPv4 address 45.11.59.229, which is advertised as belonging to AS43641 SOLLUTIUM EU Sp z.o.o. in the Netherlands. The authoritative name servers are ns1.timeweb.ru, ns2.timeweb.ru, ns3.timeweb.org and ns4.timeweb.org. No TLS certificate is presented, meaning connections are unencrypted.
The page title returned by the server is the literal domain name, providing no additional context. VirusTotal scans show that ten of ninety‑five security vendors flagged the domain, and the site appears on a single external blocklist. Google Safe Browsing classifies it as a social‑engineering threat, and the anti‑phishing service PhishDestroy has already blocked it. The domain is currently listed as offline, but the underlying infrastructure remains observable. The evidence confirms a crypto‑scam vector that leverages the Coinbase brand to lure victims, yet the specific payload or credential‑capture mechanisms have not been publicly disclosed.
Defenders should incorporate the IPv4 address and the four timeweb name servers into network‑level deny lists, and ensure that any outbound connections to the domain are halted. Updating URL filtering solutions with the domain name and the associated Google Safe Browsing and PhishDestroy identifiers will reduce exposure. Continuous monitoring of SOLLUTIUM‑owned address space for similar patterns is advised, as the registrar and hosting provider have been used in prior campaigns. Threat‑intel sharing platforms should be notified of the detection counts and blocklist presence to improve community awareness.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 13/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ICANN OVERSIGHT
Registration: infopayments-coinbase.com
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain infopayments-coinbase.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo