coinassetinvest[.]com
“coinassetinvest.com - About Us”
coinassetinvest.com — Последний известный активный (HTTP 302). Тип мошенничества: Investment Scam. Сводка доказательств: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); PhishDestroy score 100/100. Регистратор: Sav.com.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
coinassetinvest.com was observed on 2026-07-12 as an active malicious site. The domain was registered on 2025-01-09 through Sav.com, LLC and currently resolves to IP 198.12.80.250, hosted by AS36352 (HostPapa) in the United States. The site presents an HTTP 302 redirect and serves a TLS certificate from Let’s Encrypt with an E7 identifier. The only visible page title is “coinassetinvest.com - About Us”. Scamadviser assigns a trust score of 1/100, indicating extreme low credibility.
VirusTotal analysis shows that 10 out of 95 scanned security vendors flag the domain as malicious. The domain appears on one public security blocklist and is listed as blocked by PhishDestroy. The threat type is recorded as an investment scam, aligning with the domain name’s suggestion of financial services. Only a single nameserver is listed, which is typical for domains hosted on shared services.
The combination of a low trust score, a high‑risk rating, and multiple vendor detections suggests a purposeful phishing or fraud operation targeting investors. The presence of a 302 redirect may be used to route victims to credential‑harvesting pages or to hide the final payload location. However, the content behind the redirect has not been captured, so the exact phishing kit or credential‑capture mechanism remains unknown.
Defenders should add 198.12.80.250 to network deny lists and block DNS resolution for coinassetinvest.com at perimeter controls. Monitoring of outbound connections to the HostPapa AS for anomalous activity is advised. Since the domain is already listed on PhishDestroy, updating internal blocklists and threat intelligence feeds will reduce exposure. Continuous re‑evaluation is recommended in case the infrastructure changes or additional indicators emerge.
Сигналы безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание