cryptnetworkweb3[.]com
“Home - Cryptnetworkweb3 - A crypto buy and sell marketplace”
cryptnetworkweb3.com — Контент недоступен. Олицетворение бренда: Coinbase; Тип мошенничества: Wallet/seed Phishing. Сводка доказательств: VirusTotal 5/95 (alphaMountain.ai, CyRadar, ESET, Fortinet, Seclookup); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 85/100. Регистратор: Dynadot.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of cryptnetworkweb3.com indicates a high‑confidence malicious infrastructure supporting a wallet/seed phishing campaign that pretends to be associated with Coinbase. The domain was registered through Dynadot LLC on July 31 2025 and resolves to the IP address 198.251.89.220, which is announced by AS53667 (FranTech Solutions) and geolocated to the United States. The site operated without an SSL certificate and used Cloudflare authoritative nameservers dion.ns.cloudflare.com and opal.ns.cloudflare.com. The page title returned by the HTTP response reads “Home - Cryptnetworkweb3 - A crypto buy and sell marketplace”, which aligns with the reported scam type of “Wallet/Seed Phishing”.
VirusTotal scans show five of ninety‑five security vendors flagging the domain, and the domain appears on four independent blocklists: PhishDestroy, Polkadot, Enkrypt, and Codeesura. Independent reputation services assign extremely low trust scores, with Gridinsoft reporting 1 / 100 and Scamadviser also reporting 1 / 100. The domain is currently offline, and no SSL certificate is present, which may indicate that the operators have taken the site down or are rotating infrastructure. The available evidence confirms the presence of brand impersonation targeting Coinbase users, but the exact phishing payload, landing page structure, and any associated command‑and‑control servers have not been captured in the current intelligence set.
Defenders should continue to block the domain at perimeter filters, monitor the associated IP range for repeat activity, and update endpoint detection rules with the observed detection signatures from VirusTotal and the listed blocklists. Threat‑intel teams should also consider enriching this indicator with passive DNS and certificate transparency logs to detect any future re‑use of the same registrar, nameservers, or hosting provider. Ongoing observation of the four blocklists will provide early warning if the domain re‑appears.
Сигналы безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание