coinbaase-login[.]framer[.]ai
“Coinbase Login | Secure Access to Your Crypto Portfolio”
coinbaase-login.framer.ai — Контент недоступний. Уособлення бренду: Coinbase; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 16/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, CRDF, CyRadar); URLScan malicious verdict; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 100/100. Реєстратор: CSC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain coinbaase-login.framer.ai has been identified as a brand impersonation phishing site specifically targeting Coinbase, a popular cryptocurrency platform. This domain is currently offline, having been taken down after security researchers and threat intelligence systems flagged it as malicious. The site was designed to deceive users into believing they were accessing the legitimate Coinbase login portal, with a page title reading 'Coinbase Login | Secure Access to Your Crypto Portfolio' to lend an air of authenticity.
Technical analysis reveals that the domain was flagged by 16 out of 95 security vendors on VirusTotal, a significant indicator of malicious intent. The domain was registered through CSC Corporate Domains, Inc. and was created on January 06, 2018, suggesting it may have been repurposed for phishing after being dormant. It resolves to IP address 52.223.52.2 and appears on 2 security blocklists. The SSL certificate was issued by Let's Encrypt (E8), which is common among legitimate sites but is also frequently abused by phishers. Google Safe Browsing has flagged the domain for phishing, providing an additional layer of confirmation.
Given that the site is now offline, immediate risk to users is low, but vigilance is still advised. Users should always double-check URLs before entering credentials, especially for financial services like Coinbase. The legitimate Coinbase domain is coinbase.com, and any variation—such as 'coinbaase-login.framer.ai'—should be treated as suspicious. PhishDestroy recommends using password managers and enabling two-factor authentication to reduce the impact of credential theft. If you have already entered information on this site, change your Coinbase password immediately and contact Coinbase support for further assistance.
Сигнали безпеки
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 4 identified
Framer is a no-code web design platform for designing and publishing responsive websites.
www.framer.com 100% впевненостіReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога