cloud-base-extension-coin[.]pages[.]dev
“Coinbase Chrome Extension – Secure Wallet Access”
保存済み観測
観測されたタイトルの差異
PhishDestroy identifies the domain cloud-base-extension-coin.pages.dev as a generic phishing host active since seed 01ce28. This page is being tracked for potential crypto drainer activity, likely targeting cryptocurrency users by impersonating legitimate cloud-based extensions or services. No specific drainer kit fingerprint has been publicly documented, but the page structure and deployment via Pages.dev suggest a lightweight, Cloudflare-hosted lure designed to deceive visitors into connecting wallets or entering seed phrases. The site’s branding remains ambiguous, though the inclusion of 'coin' in the subdomain hints at a crypto-related lure. This domain resolves to IP address 188.114.97.3, a Cloudflare edge node commonly used to obfuscate origin infrastructure. It was registered through Cloudflare, Inc., leveraging the platform’s Pages service for rapid deployment and evasion. The domain holds a valid SSL certificate issued by Google Trust Services, which may help bypass browser security warnings. As of latest inspection, VirusTotal reports 6 out of 95 detection engines flagged the URL, indicating it remains under the radar. The domain has not been listed on Google Safe Browsing (GSB) at this time. Historical analysis shows no prior blocklist presence, suggesting a recently activated campaign. Current status is active and under investigation by threat intelligence teams. Users are advised to avoid interaction and consider blocking the domain at the network level. While current risk is elevated due to active availability and lack of AV detection, the absence from GSB and blocklists limits immediate protective coverage. Organizations should monitor for wallet connection prompts and seed phrase entry requests from similar domains. Remaining risk is moderate; however, rapid deployment via Pages.dev and Cloudflare suggests this campaign may scale quickly. Immediate mitigation includes DNS blocking, browser-level restrictions, and reporting to threat intelligence feeds to raise detection coverage.
ネットワークセキュリティインテリジェンス
脅威対応 Pipeline
ブロックリストの確認範囲
監視対象の外部情報源 10 件 · 保存スナップショット 2026年8月10日
フォレンジックインテリジェンス
VirusTotalによる分析
サイトパフォーマンス分析
Google PageSpeed Insights — mobile performance audit of cloud-base-extension-coin.pages.dev · checked Mar 30, 2026
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください