ladqer[.]site
“Enhance Your Beauty with Coinbase”
Kanıt özeti
On 21 February 2026 the domain ladqer.site was registered via Atak Domain. The authoritative nameservers nico.ns.cloudflare.com and piper.ns.cloudflare.com resolve the domain to the IP address 172.67.141.137, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. No TLS certificate is presented, indicating the site was served over plain HTTP. The only visible page title retrieved before takedown was “Enhance Your Beauty with Coinbase,” and the domain is explicitly linked to a brand‑impersonation campaign targeting Coinbase, classified as a crypto‑related scam. Threat intelligence feeds have listed ladqer.site on three security blocklists, and it is actively blocked by PhishDestroy, MetaMask, and SEAL.
VirusTotal analysis shows that two of ninety‑five antivirus engines flagged the domain, reinforcing the suspicion of malicious activity. The site’s current status is offline, and the risk rating has been assigned as elevated. Analysis confirms that the infrastructure is typical of fast‑flux or abuse‑of‑cloud services, using Cloudflare’s edge network to mask the true origin. The lack of SSL, combined with the deceptive page title, suggests the operator intended to lure users searching for Coinbase services.
However, the exact content of the landing page, any credential‑ harvesting forms, or additional payloads have not been captured, leaving those details unknown. Defenders should continue to block ladqer.site at network perimeter and DNS layers, monitor for any re‑registration attempts, and add the domain to internal allow‑list exclusions only after thorough verification. Continuous observation of the associated IP range (172.67.141.0/24) is advised, as Cloudflare customers frequently share the same address space. Incident response teams should also flag any outbound connections from internal hosts to this IP as suspicious and investigate potential compromise attempts related to Coinbase credential theft.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260202-5B908D- Yakalanan sayfa başlığı
- Enhance Your Beauty with Coinbase
- PDF belgesi
- PDF kanıtı
Hukuki dayanak
Kanıtın tam metni
Acceptable Use Policy: The domain ladqer.site is actively engaging in phishing activities, which constitutes a clear violation of your AUP prohibiting illegal activities and fraud.
Terms of Service: The continued operation of ladqer.site is in direct violation of your TOS, which reserves the right to suspend or terminate services for any activities that involve deception or fraud.
Applicable Laws (US):
Computer Fraud and Abuse Act (18 U.S.C. § 1030): This law prohibits unauthorized access to computers and the fraudulent use of information obtained from such access, which is relevant given the phishing nature of the domain.
CAN-SPAM Act (15 U.S.C. § 7701 et seq.): This act regulates commercial email and prohibits deceptive practices in electronic communications, which are being employed by ladqer.site.
Regulatory Note: Failure to take immediate action against ladqer.site may expose your organization to liability under both your own policies and applicable federal laws. Non-compliance could result in regulatory scrutiny and potential legal consequences.
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | maps.googleapis.com/maps-api-v3/api/js/63/13/common.js |
audit | Hunting_JS_WebAssembly |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin