conbase-authenticated-appdashboardweb[.]duia[.]ro
“Coinbase - Sign In”
Сводка доказательств
The domain conbase-authenticated-appdashboardweb.duia.ro is flagged as a Coinbase impersonation used for a crypto‑scam operation. Registration records show the domain was created on 31 August 2011 and is listed under the registrar CYBER_FOLKS S.R.L., indicating a long‑standing registration that predates the recent activity. The authoritative name servers are ns1.duiadns.net and ns2.duiadns.net, both associated with the duia.ro zone. Network analysis reveals the domain resolves to the IPv4 address 130.94.12.172, which belongs to AS154177 (LIGHT NODE LIMITED) and is geolocated in the United States. No TLS certificate is presented; the site is served over plain HTTP, a typical characteristic of fraudulent credential‑harvesting pages. The page title returned by the web server is “Coinbase – Sign In”, directly mirroring the legitimate brand’s login portal.
Reputation services provide strong evidence of malicious intent. The domain appears on a single security blocklist, where it is listed by PhishDestroy. Gridinsoft assigns a trust score of 0 out of 100, the lowest possible rating. VirusTotal reports that 14 of 93 scanners flag the domain as malicious, reinforcing the suspicion. The overall classification from the supplied intelligence is a “Crypto Scam”, confirming that the site is likely intended to capture cryptocurrency‑related credentials or to lure victims into fraudulent transactions. The current operational status is offline, which may be a temporary takedown or a shift to a different hosting location.
Defenders should continue to block the domain at perimeter firewalls, DNS filters, and proxy devices. Because the domain resolves to an IP owned by a public cloud provider, additional monitoring of the IP address for any future re‑use is advisable. Threat‑intel feeds that incorporate the registrar, name‑server, and ASN information can be enriched to catch any new domains created by the same entity.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание