coinbase-secure-en[.]pages[.]dev
Проверка домена coinbase-secure-en.pages.dev на фишинг и безопасность
“Suspected phishing site | Cloudflare”
coinbase-secure-en.pages.dev — Доступен · доступ ограничен (HTTP 403). Олицетворение бренда: Coinbase; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 17/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CRDF); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
This domain is flagged for elevated risk due to brand impersonation phishing, specifically targeting Coinbase users. Analysis indicates the domain was designed to mimic legitimate Coinbase authentication portals, likely to harvest credentials or facilitate unauthorized transactions. The threat type is confirmed as brand_impersonation, a tactic commonly used to exploit trust in well-known financial platforms. Infrastructure analysis reveals the domain coinbase-secure-en.pages.dev was registered through Cloudflare, Inc. on February 21, 2026, and resolves to the IP address 188.114.96.3 (AS13335, Cloudflare, Inc., US). It appears on one security blocklist and is blocked by PhishDestroy. VirusTotal reports 17 out of 95 security vendors flagging the domain as malicious. The SSL certificate is issued by Google Trust Services (WE1), and the page title was identified as 'Suspected phishing site | Cloudflare.' The domain is currently offline, though prior activity suggests it was operational for a limited window. Mitigation steps for this threat type include immediate blacklisting of the domain and associated IP (188.114.96.3) across all network security controls. Organizations should deploy indicators of compromise (IOCs) such as the domain, IP, and SSL certificate issuer (Google Trust Services / WE1) into endpoint detection and response (EDR) and security information and event management (SIEM) systems. Users who may have interacted with the domain should be instructed to reset credentials for Coinbase and any other financial accounts accessed during the exposure window. Monitoring for anomalous login attempts or transaction patterns linked to this campaign is recommended for at least 30 days post-exposure.
Охват данных12 recorded checks
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of coinbase-secure-en.pages.dev · checked Mar 2, 2026
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.