access-coinbse-sin[.]framer[.]media
“Sign In | Coinbase**”
access-coinbse-sin.framer.media — Контент недоступний (HTTP 404). Уособлення бренду: Coinbase; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 4/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, Google Safebrowsing); Google Safe Browsing flagged; PhishDestroy score 80/100. Реєстратор: CSC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
access-coinbse-sin.framer.media was observed hosting a page titled “Sign In | Coinbase”. The domain is registered through CSC Corporate Domains, Inc. and resolves to the Amazon Web Services address 35.71.142.77, which belongs to ASN 16509 (Amazon.com, Inc.) and is geolocated in the United States. The site employed a Let’s Encrypt certificate (E7) and advertised HSTS and HTTP/3 support, while the underlying stack was identified as Framer Sites running React. Google Safe Browsing has classified the domain as a social‑engineering threat, and PhishDestroy has added it to its blocklist; it also appears on a single additional security blocklist.
VirusTotal analysis recorded four positive detections out of ninety‑three scanners. The HTTP response returned a 404 status, and the domain has since been taken offline. The page title and the declared “Crypto Scam” tag indicate an attempt to impersonate the Coinbase brand, targeting users with credential‑harvesting or crypto‑related fraud. Evidence of the impersonation is limited to the page title and the brand target field; no further content was captured before the takedown, so the exact phishing workflow remains unknown.
Defenders should continue to block the domain at DNS and proxy layers, monitor the associated IP range for any re‑use, and add the domain to internal threat‑intel feeds. Because the infrastructure relies on a shared AWS name‑server set (ns‑97.awsdns‑12.com, ns‑1854.awsdns‑39.co.uk, ns‑535.awsdns‑02.net, ns‑1...), any future sub‑domains created under the same registrar may inherit similar characteristics and should be scrutinized. Ongoing vigilance is advised, especially for users receiving unsolicited Coinbase‑related login prompts, and any observed traffic to this host should be logged and investigated.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com 100% впевненостіReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога