coinbasemedia[.]com
“coinbasemedia.com”
Resumo das evidências
The domain coinbasemedia.com is currently listed as an offline crypto‑scam site that impersonates the Coinbase brand. Registration data show the domain was created on 27 Oct 2025 through Dynadot LLC and is served by the authoritative name servers ns1.dyna-ns.net and ns2.dyna-ns.net. DNS resolution points to the IPv4 address 199.59.243.228, an Amazon.com, Inc. host (AS16509) located in the United States. No TLS certificate is present, and an HTTP GET returns a 200 status code, indicating that the web server is reachable despite the offline flag. The page title returned by the server is the literal string “coinbasemedia.com”, providing no additional branding cues.
Security telemetry indicates the domain appears on a single blocklist and is explicitly blocked by PhishDestroy. AlienVault OTX has recorded the domain in one threat‑intel pulse, and VirusTotal analysis shows 16 of 95 scanning engines flag the host as malicious. The observed payload aligns with an “Airdrop Scam” phishing kit, a known pattern used to lure cryptocurrency users with false airdrop offers. The overall classification is a crypto‑scam that leverages the reputable Coinbase identity to deceive victims. Evidence gaps remain regarding the exact content served at the URL, as the site has been taken offline and no visual or form data have been captured.
Consequently, analysts cannot confirm the presence of credential‑stealing fields or redirection behavior. Defenders should continue to enforce URL filtering for coinbasemedia.com, add the IP 199.59.243.228 to network‑level blocklists, and monitor for any future re‑registration of the domain or similar look‑alike variations. Updating endpoint and email security policies to flag communications referencing “airdrop” or “Coinbase” from unauthenticated sources will further reduce exposure. Ongoing threat‑intel feeds should be consulted for any resurgence of the Airdrop Scam kit or related infrastructure reuse.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Status do domínio
Acessível → Inacessível
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
-
Status do domínio
Inacessível → Acessível
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo