pc[.]coinbase-coin[.]top
“Coinbase”
Сводка доказательств
PhishDestroy's investigation into pc.coinbase-coin.top reveals a brand impersonation threat specifically targeting Coinbase, a well-known cryptocurrency exchange. This domain was created on November 3, 2025, and registered through Gname.com Pte. Ltd. It has since been taken offline, but its short-lived presence posed a significant risk to unsuspecting users.
Technical analysis shows that the domain resolved to IP address 188.114.96.3 and lacked an SSL certificate, which is a major red flag for any site handling sensitive financial data. It was flagged by 18 of 95 VirusTotal security vendors and appeared on two blocklists, indicating widespread recognition as malicious. The page title was simply "Coinbase," a clear attempt to deceive visitors into believing they were on the legitimate Coinbase platform.
Given that the domain is now offline, the immediate threat is mitigated. However, users should remain vigilant, as similar domains may appear. PhishDestroy recommends always verifying URLs before entering credentials or financial information, using official apps or bookmarked links, and enabling two-factor authentication on all cryptocurrency accounts. If you have already interacted with this domain, change your passwords immediately and contact Coinbase support.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Registration: coinbase-coin.top
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain coinbase-coin.top behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание