moz-extension-getstarted-coinbase-extension[.]pages[.]dev
“Coinbase Wallet - Your key to the world of crypto”
Riepilogo delle prove
Analysis dated July 24 2026 identifies the domain moz-extension-getstarted-coinbase-extension.pages.dev as an offline site used for brand impersonation of Coinbase. The site resolves to 188.114.97.3, a Cloudflare‑hosted address located in the United States under ASN 13335. Nameserver records point to coco.ns.cloudflare.com and kellen.ns.cloudflare.com, confirming Cloudflare registration. The TLS certificate is issued by Google Trust Services (WE1), indicating a valid HTTPS endpoint despite the malicious purpose. HTTP response code 451 was returned, and the server advertises HSTS, Cloudflare, and HTTP/3 support.
The page title “Coinbase Wallet – Your key to the world of crypto” directly references Coinbase, aligning with the declared brand‑impersonation scam type. The domain appears on three independent blocklists—PhishDestroy, MetaMask, and SEAL—and is listed in three security blocklists overall. VirusTotal analysis shows nine of ninety‑one scanners flag the domain, and Gridinsoft assigns a trust score of 0 / 100, reinforcing the high‑risk assessment. Infrastructure evidence suggests the operator leveraged Cloudflare’s free tier to obtain a trusted certificate and hide behind a globally distributed edge network, a common tactic for rapid takedown evasion. The current offline status prevents direct content inspection, leaving the exact page payload unknown.
However, the combination of brand‑specific page title, blocklist presence, low trust score, and multiple vendor detections provides sufficient confidence to classify the domain as an elevated‑risk brand‑impersonation vector. Defenders should continue to block the domain at network perimeter and DNS layers, update URL filtering lists with the full domain, and monitor for any re‑registration or similar sub‑domains using the same naming pattern. Incident response teams should also alert users of Coinbase‑related phishing attempts and advise verification of URLs before credential entry.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 13/08/2026
8 fonti esterne monitorate Nessuna corrispondenza
Tecnologie
3 tecnologie identificate con alta affidabilità
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of moz-extension-getstarted-coinbase-extension.pages.dev · checked Jul 5, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo