web-ext-coin-pro[.]pages[.]dev
web-ext-coin-pro.pages.dev için kimlik avı ve güvenlik kontrolü
“Coinbase Chrome Extension - Secure Crypto Access™”
web-ext-coin-pro.pages.dev — Ulaşılabilir · erişim kısıtlı (HTTP 403). Marka kimliğine bürünme: Coinbase; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 1/94 (LevelBlue); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 71/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
PhishDestroy identifies the active domain web-ext-coin-pro.pages.dev as a generic phishing host designed to harvest Web3 wallet credentials under the guise of a bogus browser extension. The page mimics legitimate crypto tools, luring victims with promises of enhanced functionality while secretly exfiltrating private keys and seed phrases. Evidence suggests a drainer kit is in use, though the exact payload remains under analysis. This campaign targets users searching for Chrome or Firefox extensions that interact with blockchain networks, with traffic likely driven by SEO poisoning and paid ads pointing to the Cloudflare Pages subdomain. The threat is categorized as credential theft with potential fund loss once wallets are compromised.
Technical indicators confirm the following: the domain resolves to IP 172.66.47.50, is registered through Cloudflare, Inc., and secured with a Google Trust Services SSL certificate. VirusTotal currently shows 1/95 detections, indicating it remains undetected by most antivirus engines. The domain is served from Cloudflare Pages, a platform often abused by threat actors for rapid deployment and bulletproof hosting. Although the creation date is not publicly available due to Cloudflare’s privacy protections, the active status and zero detections imply recent deployment. Google Safe Browsing (GSB) has not yet flagged the domain, and no public blocklists currently include it. These factors contribute to a high dwell time, increasing the risk of successful victim engagement.
The domain remains active and under investigation, with the current risk level classified as 'under_investigation.' PhishDestroy continues to monitor the host via behavioral analysis and sandbox detonation to identify new payloads or infrastructure pivots. Users are advised to avoid visiting web-ext-coin-pro.pages.dev or any related links offering 'crypto extensions.' Validate browser add-ons exclusively through official stores and verify developer credentials. Organizations should implement DNS filtering rules to block the IP 172.66.47.50 and monitor internal endpoints for outbound connections to this domain. Remaining risk is assessed as elevated due to the lack of detection coverage and ongoing operational status.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of web-ext-coin-pro.pages.dev · checked Apr 13, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.