Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is support@webnic.cc.
The latest stored availability evidence still shows the domain reachable; 7 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
coinbit[.]live
“COINBIT | Play at the best online casino based on Blockchain”
coinbit.live — Непроверенный. Олицетворение бренда: Cryptoscam; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 13/91 (alphaMountain.ai, Bfore.Ai PreCrime, BitDefender, CRDF, CyRadar); URLQuery 2 alerts; URLScan malicious verdict; PhishDestroy score 100/100. Регистратор: Web Commerce Communica….
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
coinbit.live is currently active and classified as a high‑risk generic phishing domain as of July 12 2026. The site advertises itself with the page title “COINBIT | Play at the best online casino based on Blockchain”, indicating a cryptocurrency‑focused lure. HTTP requests return a 200 status code, confirming the front‑end is reachable and serving content.
Infrastructure analysis shows the domain resolves to a single IPv4 address, 69.5.189.58. The address is allocated to AS42624 (Global‑Data System IT Corporation) and is geolocated in Switzerland. Authoritative name servers are ns1.nameserverhub.com, ns2.nameserverhub.com, ns3.nameserverhub.com, and ns4.nameserverhub.com. The site uses a Let’s Encrypt (YR1) SSL certificate, and both Gridinsoft and Scamadviser assign a trust score of 1 / 100, reflecting extreme suspicion of the host.
Threat intelligence links the site to the “Gambler Scam” phishing kit, a known package used to harvest credentials for cryptocurrency‑related services. The domain is registered through Web Commerce Communications Limited and is recorded as a cryptocurrency scam type. VirusTotal analysis shows 7 out of 95 security vendors flag the domain, and it appears on one external security blocklist. PhishDestroy has already blocked the domain, underscoring its malicious intent.
Defenders should block the IP address 69.5.189.58 and the four nameserver hostnames at both network perimeter and host‑based firewalls. URL filtering policies must deny any request containing the “coinbit.live” hostname. Continuous monitoring of the IP reputation and periodic re‑scans with VirusTotal are recommended, as additional detections may emerge. Internal users receiving unsolicited communications that reference “COINBIT” or blockchain‑based casino offers should be instructed to block the URL, isolate any credential submissions, and report the incident to the security team for further investigation.
Сигналы безопасности
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | coinbit.live |
malicious | Sinkholed |
| DNS4EU | coinbit.live |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
PD-1767580134-coinbit.live Recipient: support@webnic.cc Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание