coinbaseproologinz[.]webflow[.]io
“Coinbase Pro | Digital Asset Exchange”
coinbaseproologinz.webflow.io — Контент недоступний. Уособлення бренду: Coinbase; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 13/95 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 94/100. Реєстратор: MarkMonitor.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of coinbaseproologinz.webflow.io indicates a high‑risk brand‑impersonation campaign targeting Coinbase users. The domain, registered on May 08 2013 through MarkMonitor, Inc., resolves to 172.64.151.8, an address owned by Cloudflare (AS13335, United States). DNS resolution uses Cloudflare name servers journey.ns.cloudflare.com and lamar.ns.cloudflare.com, and the site serves content over HTTP/3 with a Google Trust Services / WE1 SSL certificate, suggesting a legitimate‑looking TLS configuration. The page title returned by the server is “Coinbase Pro | Digital Asset Exchange,” directly referencing the Coinbase brand, and Google Safe Browsing classifies the site as social engineering.
Scamadviser assigns a trust score of 1 / 100, and the domain appears on at least one security blocklist. VirusTotal records show that 13 of 95 scanning engines have flagged the domain, reinforcing the malicious assessment. The HTTP response is a 404, and the current operational state is offline, with the site reported as taken down and blocked by the PhishDestroy feed. The evidence confirms a deliberate attempt to impersonate Coinbase’s professional trading platform, likely to harvest credentials or lure victims into a crypto‑related fraud.
While the exact phishing page content has not been captured, the combination of brand‑specific title, low trust score, multiple vendor detections, and blocklist inclusion provides sufficient confidence to treat the domain as malicious. Defenders should add the domain and its associated IP address (172.64.151.8) to network‑level blocklists, enforce DNS sink‑hole rules for the Cloudflare name servers, and monitor for any traffic to the domain or similar Webflow‑hosted subdomains that reference Coinbase. Incident response teams should also alert users of the Coinbase brand about the impersonation attempt and advise them to verify URLs before entering credentials.
Сигнали безпеки
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога