Güvenlik raporuna geç
⚠️
Bu alan adı, zararlı olarak işaretlenmiştir
Güvenlik motorları bir algılama bildiriyor: 13. Çok dikkatli olun — kimlik bilgilerini veya kişisel bilgileri girmeyin.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
6 months
Reports sent
1
Current status
HTTP 502 at latest stored check
Etki alanı güvenliği ve tehdit istihbaratı

coinvault[.]live

“Coinbase Vault”

Tehdit kararı Kritik 95/100 kanıt puanı
Kullanılabilirlik Sunucu hatası En son saklanan yanıt sonuçsuz kaldı
VirusTotal algılamaları: 13/91 Marka kimliğine bürünme: Coinbase
OTX: 3 refs 20.01.2026 Coinbase 1 Report Sent

Kanıt özeti

KRİTİK
Evidence score
95/100

The domain coinvault.live is identified as a high-risk brand impersonation threat targeting Coinbase users. Analysis confirms it operates as a phishing site, presenting a fraudulent 'Coinbase Vault' interface to deceive victims into submitting sensitive account credentials. The domain is currently offline but was actively used in malicious campaigns prior to takedown. Infrastructure analysis reveals the domain was registered on February 21, 2026, through NameSilo, LLC, and resolved to the IP address 80.78.22.230, hosted on AS39287 (Materialism s.r.l., Denmark). Security assessments indicate 19 of 95 vendors on VirusTotal flagged the domain as malicious, while three independent blocklists included it in their denylists. The site lacked SSL encryption, further increasing exposure risks for visitors. Detection systems such as PhishDestroy, MetaMask, and SEAL had already blocked access, and Google Safe Browsing classified it as a phishing threat. Although coinvault.live is now offline, similar threats may re-emerge under different domains. Users are advised to verify domain authenticity before entering credentials, enable multi-factor authentication on financial platforms, and cross-reference security warnings from browser-based protection systems. Organizations should monitor for newly registered domains mimicking legitimate brands and update blocklists with confirmed malicious indicators, including the IP 80.78.22.230 and the domain creation date.

Gönderilen kanıt anlık görüntüsü

Gönderildi
Kayıt defteri kayıtları
1
Vaka kimliği
PD-20260120-09C63D
Yakalanan sayfa başlığı
Coinbase Vault
PDF belgesi
PDF kanıtı
Kanıtın tam metni
Policy Violations:
Section 3.1 of AUP: The domain coinvault.live is engaged in phishing activities, which are explicitly prohibited under your Acceptable Use Policy.
Section 4.2 of TOS: The registrar reserves the right to suspend or terminate services for any activities that involve fraud or deception, both of which are evident in the operation of this domain.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, which is relevant as phishing schemes typically involve deceitful access to personal information.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities via electronic communications, applicable to the fraudulent activities associated with coinvault.live.
Anti-Phishing Act (15 U.S.C. § 7704): This act specifically addresses the illegal use of misleading electronic communications to solicit personal information, which is directly relevant to the operations of this domain.
Regulatory Note: Failure to take immediate action against this domain may result in regulatory scrutiny and potential liability for facilitating illegal activities. Compliance with your AUP and TOS is essential to avoid further legal repercussions.
VirusTotal
VirusTotal
13 det.
URLQuery
URLQuery
100 det.
OTX references
Gözlemlenen durum
Sunucu hatası HTTP 502
PhishDestroy
DestroyList
Listelenmiş
Reports Sent
1

Data Coverage

VirusTotal 13 / 91 URLQuery 100 det. PhishStats checked — no match recorded OTX 3 community references CF Radarı scan completed URLScan capture saklanan rapor URLScan verdict malicious DNS engellemeleri kontrol edilmedi TLS sertifika verisi yok WHOIS not parsed Ekran görüntüsü 3 captures · 3 sources Yönlendirme zinciri araştırılmadı
Ağ Güvenliği İstihbaratıRegistrar context
Registrar context NameSilo
Stored registration data identifies NameSilo as the registrar. PhishDestroy maintains separate registrar investigations; that broader material is contextual and is not an independent detection for this domain.
Review source investigation

Tehdit Müdahale Pipeline

Keşif
Checks
Reports
Erişilebilirlik
13/14

Engelleme listesi kapsamı

10 izlenen harici kaynak · kayıtlı anlık görüntü 10.08.2026

10 izlenen harici kaynak Eşleşme yok

Tespit zaman çizelgesi

  1. Cloudflare Radar

    Cloudflare Radar taraması kaydedildi · Taramayı aç

Kaydedilen görüntü

Sayfa başlığı
Coinbase Vault
Impersonates
Coinbase

Etki Alanı Analizi

Alan adı
URLScan Verdict Zararlı score 100 Phishing brand: Coinbase report ↗
Google Safe Browsing İşaretlendi Social engineering checked 25.02.2026
Sunucu / ASN nginx/1.22.1 · AS39287 Materialism s.r.l.
IP itibarı IP abuse confidence 0/100 0 reports checked 01.08.2026
Kayıt kuruluşu NameSilo US(US) PhishDestroy Investigation
IP adresi 80.78.22.230 DK
Coğrafi konumDK Copenhagen, DK
AS39287 · Materialism s.r.l.
KayıtExpires 19.01.2027
HTTP Durumu502 Error
Elapsed Since First Report 34 days
Neyi ölçüyoruz Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Sunucu hatası.
Her raporun içeriği Saklanan giden rapor kayıtları, satıcı kararları, kayıt verileri, barındırma ayrıntıları, sınıflandırmalar veya ekran görüntüleri gibi o sırada mevcut olan kanıtlara referans verebilir. Bu sayfa, teslim edilen yükün, alındığının, onaylandığının veya alıcının yaptığı eylemin tam olarak ne olduğu konusunda bir sonuç çıkarmaz.
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
İlk Kez Tespit Edildi20.01.2026
DOM Analysisanalyzed 24.03.2026DOM analysis score 10/1001 brand signal
Submitted URLhttp://coinvault.live/
Ad sunucularıns1.dnsowl.comns2.dnsowl.comns3.dnsowl.com
TLS gözlemi20.01.2026 tarihinden itibaren geçerli08.08.2026 tarihinde tarandı
ICANN OVERSIGHT

Akreditasyon ve RAA bağlamı

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Hiçbir şey otomatik olarak gönderilmez.

Adli İstihbarat

External Scripts 1
https://performance.radar.cloudflare.com/beacon.js
Bu Alan Adını Bildir Kanıt sunun ve başkalarını korumaya yardımcı olun

VirusTotal Analizi

13 / 91 güvenlik sağlayıcıları bu alanı işaretledi
View on VT
Last analyzed Previous stored snapshot: 19 detections
ADMINUSLabs
alphaMountain.ai
BitDefender
Chong Lua Dao
CRDF
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Lionic
Sophos
VIPRE

Bu Siteden Etkilendiniz mi?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.

Europol
AB ülkeniz için resmi raporlama kanalını bulun
National police directory
Kurtarma dolandırıcılarına dikkat edin! Suçlular, araştırmacı, avukat veya kurtarma görevlisi gibi davranarak mağdurlarla tekrar iletişime geçebilir. Peşin ücret ödemeyin veya kimlik bilgilerinizi paylaşmayın. Geri ödeme dolandırıcılığı hakkında daha fazla bilgi edinin →

Yerel Yetkililere Bildirin

resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.

97 ülke rehberi
Yapay zeka destekli taslak — olay ayrıntıları yapay zeka sağlayıcısı tarafından işlenir Kendiniz inceleyin ve gönderin

Herhangi Bir Alan Adını Kontrol Et

Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi

Şimdi Tara

Oltalama Olayını Bildir

Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun

Bildir

Canlı Tehdit Akışı

Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri

İzle

Gelişmelerden Haberdar Olun, Güvende Kalın

Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin

Canlı Tehdit Akışı Bu İlanı İtiraz Et

Harici araçlar

HTML · IFRAME

Bu Raporu Yerleştir

Bu tehdit bilgisini web sitenizde veya blogunuzda paylaşın

embed.html
<iframe
  src="https://phishdestroy.io/tr/embed/domain/coinvault.live"
  title="PhishDestroy threat report for coinvault.live"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Çok İçten Bir Teşekkür Mektubu

Hicivli taslak oluşturucu

Alıcı
Ücret bağlamı

Hicivli taslak. Ücret rakamları tahminidir; bu alan adına kesin olarak atfedildikleri iddia edilmez.