ext-conbasee[.]framer[.]ai
ext-conbasee.framer.ai 피싱 및 보안 점검
“Coinbase Extension â Secure Web3 Wallet”
ext-conbasee.framer.ai — 콘텐츠를 사용할 수 없음 (HTTP 404). 브랜드 사칭: Coinbase; 사기 유형: Brand Impersonation. 증거 요약: VirusTotal 16/94 (ChainPatrol, Chong Lua Dao, CRDF, CyRadar, ESET); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. 등록기관: CSC.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
PhishDestroy identifies ext-conbasee.framer.ai as an active Coinbase-brand impersonation phishing campaign under investigation, posing as a fraudulent 'Coinbase Extension – Secure Web3 Wallet' web page. The domain’s low detection rate and deliberate mimicry of a major cryptocurrency brand indicate a high-risk attempt to harvest user credentials and Web3 wallet access. This threat is not merely generic phishing—it is a targeted brand impersonation attack designed to exploit trust in Coinbase’s name and deceive users into installing malicious browser extensions or surrendering sensitive wallet recovery phrases. The risk level remains under investigation due to evolving infrastructure, but current indicators strongly suggest malicious intent and potential for widespread compromise.
This domain was flagged by PhishDestroy’s seed c6bdef with the following technical indicators: it resolves to IP address 31.43.161.6, hosts a Let’s Encrypt SSL certificate, and presents a page titled 'Coinbase Extension – Secure Web3 Wallet' on framer.ai’s subdomain platform. The domain currently shows 16/95 detections on VirusTotal, indicating no AV or security vendor flagging as of the latest scan. While registrar and creation date are not provided in open sources, the use of framer.ai’s platform and the immediate availability of the malicious page suggest rapid deployment for phishing purposes. It is not currently listed on major blocklists such as PhishTank, OpenPhish, or Google Safe Browsing, and WHOIS trust scores remain neutral due to the domain’s recent appearance.
To mitigate exposure to this specific threat, users must avoid accessing ext-conbasee.framer.ai or any framer.ai subdomain claiming to offer 'Coinbase Extensions' or 'Web3 Wallets.' Only download cryptocurrency-related software and browser extensions directly from the official Coinbase website (coinbase.com) or verified distribution points such as official app stores or GitHub under Coinbase’s verified account. Enable multi-factor authentication (MFA) on all crypto accounts and use hardware wallets for high-value assets. Security teams should block the IP 31.43.161.6 and monitor DNS for similar Coinbase-branded impersonations. Report any interactions with this domain to Coinbase’s abuse team and your internal security operations center. Always verify URLs via official sources before entering credentials or downloading software.
네트워크 보안 인텔리전스
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 분석
증거 및 외부 보고서
PD-20260411-C6DFDB Recipient: abuse@framer.com 이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.