8563-coinbase[.]com
“WASP Panel”
8563-coinbase.com — Контент недоступний (HTTP 502). Уособлення бренду: Coinbase; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 22/94 (ADMINUSLabs, ChainPatrol, Criminal IP, alphaMountain.ai, BitDefender); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Реєстратор: Metaregistrar BV.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain is flagged as a high-risk credential harvesting and brand impersonation threat specifically targeting Coinbase, a cryptocurrency exchange platform. Analysis indicates the infrastructure was designed to deceive users into submitting login credentials, recovery phrases, or other sensitive account information under the false pretense of official Coinbase services.
Infrastructure analysis reveals multiple technical indicators of malicious intent: the domain resolves to IP 203.159.90.28 (AS210558, 1337 Services GmbH, Netherlands), lacks SSL encryption, and displays a page title 'WASP Panel'—a known phishing kit interface. The domain was registered on March 14, 2026, through Metaregistrar BV and is currently offline. Detection metrics include 22/95 security vendor flags on VirusTotal and presence on three security blocklists (PhishDestroy, MetaMask, and SEAL). The creation date in 2026 suggests either a typographical error in records or potential pre-registration for future malicious campaigns.
Mitigation requires immediate action from both users and security teams. Users who accessed this domain should assume credential compromise and initiate password resets across all accounts using similar authentication details, with priority given to financial and cryptocurrency platforms. Security teams should implement DNS-based blocking for the domain and its resolved IP, monitor for related subdomains using the '8563-coinbase' pattern, and deploy detection rules for 'WASP Panel' page titles in HTTP headers. Network administrators should inspect logs for connections to 203.159.90.28 and associated AS210558 infrastructure, particularly from systems handling financial or cryptocurrency transactions. Given the high-risk nature of credential harvesting, affected organizations should consider proactive account lockouts and multi-factor authentication enforcement for potentially exposed users.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | 8563-coinbase.com/assets/index-bphrxwjy.js |
malware | Detects file containing Telegram Bot API |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260314-B98A7E Recipient: abuse@as210558.net Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога