cloud-base-extension-coin[.]pages[.]dev
“Coinbase Chrome Extension – Secure Wallet Access”
Збережене спостереження
Зафіксована відмінність заголовків
Зведення доказів
PhishDestroy identifies the domain cloud-base-extension-coin.pages.dev as a generic phishing host active since seed 01ce28. This page is being tracked for potential crypto drainer activity, likely targeting cryptocurrency users by impersonating legitimate cloud-based extensions or services. No specific drainer kit fingerprint has been publicly documented, but the page structure and deployment via Pages.dev suggest a lightweight, Cloudflare-hosted lure designed to deceive visitors into connecting wallets or entering seed phrases. The site’s branding remains ambiguous, though the inclusion of 'coin' in the subdomain hints at a crypto-related lure. This domain resolves to IP address 188.114.97.3, a Cloudflare edge node commonly used to obfuscate origin infrastructure. It was registered through Cloudflare, Inc., leveraging the platform’s Pages service for rapid deployment and evasion. The domain holds a valid SSL certificate issued by Google Trust Services, which may help bypass browser security warnings. As of latest inspection, VirusTotal reports 6 out of 95 detection engines flagged the URL, indicating it remains under the radar. The domain has not been listed on Google Safe Browsing (GSB) at this time. Historical analysis shows no prior blocklist presence, suggesting a recently activated campaign. Current status is active and under investigation by threat intelligence teams. Users are advised to avoid interaction and consider blocking the domain at the network level. While current risk is elevated due to active availability and lack of AV detection, the absence from GSB and blocklists limits immediate protective coverage. Organizations should monitor for wallet connection prompts and seed phrase entry requests from similar domains. Remaining risk is moderate; however, rapid deployment via Pages.dev and Cloudflare suggests this campaign may scale quickly. Immediate mitigation includes DNS blocking, browser-level restrictions, and reporting to threat intelligence feeds to raise detection coverage.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
8 зовнішніх джерел під наглядом Збігів немає
Криміналістичні дані
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of cloud-base-extension-coin.pages.dev · checked Mar 30, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога