netcoinsapp-sso-auth[.]webflow[.]io
“Netcoins | Login”
netcoinsapp-sso-auth.webflow.io — İçerik kullanılamıyor. Marka kimliğine bürünme: Netcoins; Dolandırıcılık türü: Credential Phishing. Kanıt özeti: VirusTotal 19/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Kayıt kuruluşu: MarkMonitor.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Analysis as of July 23 2026 indicates that netcoinsapp-sso-auth.webflow.io is an offline credential‑phishing site targeting users of the Netcoins service. The domain resolves to 172.64.151.8, an address owned by ASN 13335 (Cloudflare, Inc.) and is protected by Cloudflare’s edge network. The site presents the page title "Netcoins | Login", suggesting an attempt to harvest login credentials. Registration details show the domain was created on 08 May 2013 and is managed through MarkMonitor, Inc., a registrar commonly used for high‑value brands.
TLS termination is provided by Google Trust Services under the WE1 certificate, confirming a valid HTTPS configuration despite the malicious intent. An HTTP 403 response is returned when the URL is accessed, indicating the site is currently taken offline. VirusTotal scans have flagged the domain in 19 of 95 security engines, and the domain is listed on at least one public phishing blocklist, with PhishDestroy explicitly blocking it. Detected technologies include Webflow, Cloudflare, and HTTP/3, consistent with the hosting profile.
Uncertainty remains regarding the current activity of the underlying phishing infrastructure because the HTTP status reflects a takedown rather than a live service, and no additional payloads or redirects have been observed. Defenders should continue to block the domain at perimeter filters, monitor DNS queries for the associated IP address and nameservers (journey.ns.cloudflare.com, lamar.ns.cloudflare.com), and consider adding the IP to threat‑intel feeds. Ongoing reconnaissance of the Cloudflare‑hosted asset may reveal resurrection attempts, so regular re‑scanning through VirusTotal and similar services is recommended.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 3 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Arşivlenmiş Kanıtlar
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin