cobbyyhh[.]top
“Coinbase”
cobbyyhh.top — Контент недоступен. Олицетворение бренда: Coinbase; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 16/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CRDF); URLQuery 100 det.; URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 95/100. Регистратор: Gname.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of the domain cobbyyhh.top indicates a high-risk phishing campaign impersonating Coinbase, a cryptocurrency exchange platform. The domain was registered on December 12, 2025, through Gname.com Pte. Ltd., a registrar frequently associated with abusive registrations. Infrastructure analysis reveals the domain resolves to the IP address 103.108.41.18, hosted in Hong Kong under AS135581 (ONL-HK). The nameservers denver.ns.cloudflare.com and pam.ns.cloudflare.com suggest the use of Cloudflare services, which may obscure further hosting details and complicate takedown efforts. The domain has been flagged for social engineering by Google Safe Browsing, and Gridinsoft assigns it a trust score of 0/100, indicating no legitimacy.
At the time of assessment, the domain appears on one security blocklist, and 16 of 95 security vendors on VirusTotal have detected it as malicious. The absence of an SSL certificate further reduces its credibility, as modern secure sites typically enforce HTTPS. The page title explicitly displays 'Coinbase,' aligning with the reported scam type of a crypto scam, though the exact content and functionality of the site remain unanalyzed. Defenders should treat this domain as compromised infrastructure.
The use of Cloudflare nameservers and a hosting provider in a jurisdiction with limited enforcement may delay mitigation. Given its offline status as of July 23, 2026, the domain may have been taken down following abuse reports, though monitoring for re-activation is recommended. Organizations should update blocklists to include this domain and its associated IP address to prevent potential re-emergence. No evidence of a phishing kit or additional malicious domains linked to this campaign is currently available.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криминалистическая аналитика
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание