access-eng-coinbase[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Збережене спостереження
Зафіксована відмінність заголовків
Зведення доказів
Analysis of the domain access-eng-coinbase.pages.dev indicates a confirmed brand impersonation campaign targeting Coinbase, classified as a crypto scam. The domain, registered through Cloudflare, Inc. on February 21, 2026, resolved to the IP address 172.66.44.75, hosted on Cloudflare's infrastructure (AS13335) in the United States. Nameservers zita.ns.cloudflare.com and mike.ns.cloudflare.com were associated with the domain, reinforcing its Cloudflare-hosted status. At the time of assessment, the domain returned an HTTP 403 status with the page title 'Suspected phishing site | Cloudflare,' suggesting it had been flagged and restricted by the hosting provider. Detection data reveals limited but actionable intelligence: four of ninety-three security vendors on VirusTotal flagged the domain as malicious, while PhishDestroy explicitly blocked it.
The domain appears on at least one security blocklist, and Gridinsoft assigned a trust score of 0/100, further corroborating its malicious classification. The SSL certificate, issued by Google Trust Services (WE1), does not mitigate the risk, as phishing domains frequently leverage valid certificates to appear legitimate. Infrastructure analysis reveals the use of HTTP Strict Transport Security (HSTS), a security feature that, while typically associated with legitimate sites, can be exploited to lend credibility to phishing domains. The domain's current offline status suggests mitigation efforts, though defenders should remain vigilant for re-emergence under similar infrastructure or naming conventions.
Given the targeting of Coinbase, a cryptocurrency exchange, the campaign likely aimed to harvest credentials or facilitate fraudulent transactions. Defenders are advised to block the domain and its associated IP (172.66.44.75) at the network level, monitor for related subdomains or newly registered lookalike domains, and alert users to the impersonation risk.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 10.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
Статус домену
Доступний → Недоступний
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Технології
Виявлено 2 технології з високою впевненістю
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of access-eng-coinbase.pages.dev · checked Apr 11, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога