get-extension-bas[.]pages[.]dev
Проверка домена get-extension-bas.pages.dev на фишинг и безопасность
“Coinbase Extension - Coinbase Browser Extension [Full Guide]”
get-extension-bas.pages.dev — Доступен · доступ ограничен (HTTP 403). Олицетворение бренда: Coinbase; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 3/95 (ChainPatrol, alphaMountain.ai, Phishing Database); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, get-extension-bas.pages.dev, is under investigation for brand impersonation targeting Coinbase users. Analysis indicates the site masquerades as an official Coinbase browser extension download portal, presenting a high-risk vector for credential theft or malware distribution. The domain is currently offline but remains a documented threat in security databases. Infrastructure analysis reveals the domain was registered through Cloudflare, Inc. and resolves to the IP address 172.66.47.5. It was created on February 22, 2026, and employs security features such as HSTS and HTTP/3, likely to evade detection. Despite these measures, the domain has been flagged by 0 of 95 VirusTotal vendors, though it appears on 3 security blocklists. Additional technical indicators include a Google Trust Services SSL certificate and detection by MetaMask, SEAL, and PhishDestroy. The page title, 'Coinbase Extension - Coinbase Browser Extension [Full Guide],' reinforces the impersonation tactic. The domain’s current offline status does not eliminate its risk, as threat actors frequently reactivate such infrastructure. Organizations and users are advised to block the domain and associated IP (172.66.47.5) at the network level. Security teams should monitor for reactivation attempts and update endpoint protection rules to include this indicator. Users who may have interacted with the site should revoke any associated browser extensions and reset credentials for cryptocurrency platforms as a precaution.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of get-extension-bas.pages.dev · checked Jun 26, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание