auth-sso-coinbasepro--sso[.]webflow[.]io
“Official Website® of |Coinbase Pro: | Digital Asset Exchange®”
auth-sso-coinbasepro--sso.webflow.io — Контент недоступний. Уособлення бренду: Coinbase; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 15/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); URLScan malicious verdict; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 100/100. Реєстратор: MarkMonitor.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain auth-sso-coinbasepro--sso.webflow.io was created on May 08, 2013 and is currently listed as offline. Technical analysis shows it resolves to 104.18.36.248, an address owned by Cloudflare (ASN13335) located in the United States. The domain uses Cloudflare’s DNS service, with authoritative name servers journey.ns.cloudflare.com and lamar.ns.cloudflare.com, and serves content over HTTP/3. The TLS certificate presented is issued by Google Trust Services under the WE1 profile, indicating a valid HTTPS handshake despite the malicious intent.
The HTTP response returns a 404 status code, and the page title captured from the site reads "Official Website® of |Coinbase Pro: | Digital Asset Exchange®," directly mimicking the Coinbase brand. Google Safe Browsing classifies the site as a social engineering threat, and 15 of 95 VirusTotal scanners flag it as malicious, confirming a consensus among security vendors. PhishDestroy has added the domain to its blocklist, and it appears on one additional security blocklist. Scamadviser assigns a trust score of 1/100, reflecting extreme risk.
The registrar listed is MarkMonitor, Inc., a common registrar for brand‑protected domains, suggesting the registration may have been compromised or leveraged for abuse. The observed indicators collectively point to a high‑risk brand‑impersonation campaign targeting Coinbase users with a crypto‑scam payload. Uncertainty remains regarding the exact payload or phishing page content, as the site returns a 404 and no further content has been captured. Defenders should block the domain at network perimeters, update URL filtering and endpoint protection feeds with the observed indicators, and monitor for any future re‑activation of the domain or related sub‑domains.
Сигнали безпеки
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога