MALICIOUS — CRITICAL
base-browser-extension.pages.dev için kimlik avı ve güvenlik kontrolü
base-browser-extension[.]
This domain, base-browser-extension.pages.dev, is flagged as an active brand impersonation threat targeting Coinbase users.
- VirusTotal
- 6/94
- Blocklists
- No stored match
- Kullanılabilirlik
- İçerik kullanılamıyor · HTTP 451
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
base-browser-extension.pages.dev — İçerik kullanılamıyor (HTTP 451). Marka kimliğine bürünme: Coinbase; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 6/94 (ADMINUSLabs, CyRadar, Fortinet, Kaspersky, LevelBlue); URLScan malicious verdict; PhishDestroy score 73/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
This domain, base-browser-extension.pages.dev, is flagged as an active brand impersonation threat targeting Coinbase users. Analysis indicates the page masquerades as the Coinbase Wallet Extension under the title 'Coinbase Wallet Extension - Secure Web3 Access,' attempting to deceive users into installing malicious browser components. The infrastructure appears designed to harvest cryptocurrency wallet credentials or deploy crypto drainer functionality, though no specific drainer kit signature has been confirmed at this time. Infrastructure analysis reveals the domain was registered through Cloudflare on March 25, 2026, resolving to IP address 172.66.47.49 (Cloudflare, Inc., CA). The domain appears on one security blocklist and is flagged by 6 of 95 security vendors on VirusTotal. The SSL certificate is issued by Google Trust Services (WE1), a common pattern observed in both legitimate and malicious Cloudflare-hosted domains. No Google Safe Browsing detections were reported at the time of analysis. The domain remains active as of the latest verification, though it has been blocked by at least one security provider. Response actions should include immediate blacklisting of the domain and IP across security gateways, as well as monitoring for related subdomains or newly registered lookalike domains. Users are advised to verify browser extensions exclusively through official vendor marketplaces and to inspect SSL certificates for anomalies. The remaining risk is classified as high due to the domain's active status and direct targeting of cryptocurrency wallet credentials, which could lead to immediate financial loss if successful.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Adli İstihbarat
Teknolojiler · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of base-browser-extension.pages.dev · checked Apr 2, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.