sso-coinbasepro-cdn-e--auth[.]webflow[.]io
“Official Site® | Coinbase Pro | Digital Asset Exchange®”
sso-coinbasepro-cdn-e--auth.webflow.io — İçerik kullanılamıyor. Marka kimliğine bürünme: Coinbase; Dolandırıcılık türü: Crypto Scam. Kanıt özeti: VirusTotal 13/95 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 89/100. Kayıt kuruluşu: MarkMonitor.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, sso-coinbasepro-cdn-e--auth.webflow.io, is hosted on a Cloudflare edge server (IP 172.64.151.8, AS13335, United States) and serves an HTTP/3 endpoint that currently returns a 404 status code. The site presents the page title “Official Site® | Coinbase Pro | Digital Asset Exchange®”, indicating a direct attempt to masquerade as Coinbase’s professional trading platform. Registration data shows the domain was created on 08 May 2013 and is listed with the registrar MarkMonitor, Inc., a service commonly used by legitimate enterprises. The TLS certificate is issued by Google Trust Services under the WE1 authority, and the authoritative nameservers are journey.ns.cloudflare.com and lamar.ns.cloudflare.com, both consistent with the Cloudflare hosting profile.
VirusTotal analysis has recorded 13 of 95 security scanners flagging the domain as malicious, and the domain appears on a single public blocklist. Independent threat‑intelligence feed PhishDestroy has also taken the domain offline, confirming that active hosting has been terminated. No additional public evidence such as screenshot archives or sandbox reports is available, so the precise malicious payload or credential‑harvesting mechanism remains unconfirmed. Defenders should add the fully qualified domain name to URL filtering and DNS‑sinkhole policies, especially any rules that target Coinbase‑related traffic.
Because the domain resolves to a Cloudflare‑owned IP, network‑level blocking should be applied to the specific IP address 172.64.151.8 only if it is known to be associated with this campaign, to avoid over‑blocking legitimate Cloudflare services. Continuous monitoring of the domain’s registrar (MarkMonitor) and its SSL fingerprint (Google Trust Services/WE1) can provide early indicators of re‑use. Threat‑intel teams should also watch for new sub‑domains that reuse the same naming pattern or reference the same page title, and update detection signatures accordingly.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Arşivlenmiş Kanıtlar
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin