mailers-coinbase[.]com
mailers-coinbase.com — Conteúdo indisponível. Representação da marca: Coinbase; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 4/93 (ChainPatrol, Fortinet, Seclookup, SOCRadar); PhishDestroy score 65/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
mailers-coinbase.com was registered on 21 February 2026 and quickly began serving a cryptocurrency‑focused impersonation campaign targeting Coinbase customers. The domain resolves to 89.37.173.2, an address owned by Hydra Communications Ltd in Switzerland (AS25369). Network analysis shows the host is currently offline, but historical records indicate the site was actively serving malicious content before takedown. The infrastructure has been listed on three independent security blocklists and is explicitly blocked by PhishDestroy, MetaMask, and SEAL, confirming its role in a crypto‑drainer operation.
VirusTotal scans recorded four positive detections out of ninety‑three engines, reinforcing the malicious classification. The site presented an SSL certificate identified as R12; while the certificate details are limited, the presence of a non‑standard certificate aligns with typical phishing deployments that use inexpensive or self‑issued TLS. The campaign leveraged the “Coinbase” brand, a known high‑value target for cryptocurrency scams, and is categorized as a crypto scam in the intelligence feed.
No public page title or content snapshot is available, so visual analysis cannot be corroborated at this time. Defenders should continue to enforce DNS‑level blocking for mailers-coinbase.com, monitor the associated IP for any resurgence, and ensure that endpoint security solutions are updated to reflect the four VirusTotal detections. Adding the domain to internal blocklists and sharing indicators of compromise with upstream threat‑share platforms will help prevent re‑use of this infrastructure in future campaigns.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência forense
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo