access-eng-coinbase[.]pages[.]dev
access-eng-coinbase.pages.dev için kimlik avı ve güvenlik kontrolü
“Suspected phishing site | Cloudflare”
access-eng-coinbase.pages.dev — Ulaşılabilir · erişim kısıtlı (HTTP 403). Marka kimliğine bürünme: Coinbase; Dolandırıcılık türü: Crypto Scam. Kanıt özeti: VirusTotal 4/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, Fortinet); PhishDestroy score 65/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Analysis of the domain access-eng-coinbase.pages.dev indicates a confirmed brand impersonation campaign targeting Coinbase, classified as a crypto scam. The domain, registered through Cloudflare, Inc. on February 21, 2026, resolved to the IP address 172.66.44.75, hosted on Cloudflare's infrastructure (AS13335) in the United States. Nameservers zita.ns.cloudflare.com and mike.ns.cloudflare.com were associated with the domain, reinforcing its Cloudflare-hosted status. At the time of assessment, the domain returned an HTTP 403 status with the page title 'Suspected phishing site | Cloudflare,' suggesting it had been flagged and restricted by the hosting provider. Detection data reveals limited but actionable intelligence: four of ninety-three security vendors on VirusTotal flagged the domain as malicious, while PhishDestroy explicitly blocked it.
The domain appears on at least one security blocklist, and Gridinsoft assigned a trust score of 0/100, further corroborating its malicious classification. The SSL certificate, issued by Google Trust Services (WE1), does not mitigate the risk, as phishing domains frequently leverage valid certificates to appear legitimate. Infrastructure analysis reveals the use of HTTP Strict Transport Security (HSTS), a security feature that, while typically associated with legitimate sites, can be exploited to lend credibility to phishing domains. The domain's current offline status suggests mitigation efforts, though defenders should remain vigilant for re-emergence under similar infrastructure or naming conventions.
Given the targeting of Coinbase, a cryptocurrency exchange, the campaign likely aimed to harvest credentials or facilitate fraudulent transactions. Defenders are advised to block the domain and its associated IP (172.66.44.75) at the network level, monitor for related subdomains or newly registered lookalike domains, and alert users to the impersonation risk.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 2 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenVirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of access-eng-coinbase.pages.dev · checked Apr 11, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin