coinbasesupports[.]net
“Site Under Maitenance”
coinbasesupports.net — Неперевірений. Уособлення бренду: Coinbase; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 16/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); URLQuery 2 alerts; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain coinbasesupports.net was registered on February 28, 2026 through Cloudflare, Inc. and resolves to the IP address 188.114.97.3, which is hosted by Cloudflare (AS13335) in the United States. No SSL certificate is presented for the site, and an HTTP request returns the page title "Site Under Maitenance". The domain is currently taken offline, but it was previously listed on three security blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL.
VirusTotal analysis shows that six of ninety‑three security vendors flagged the domain as malicious, reinforcing the suspicion that it was used for a cryptocurrency‑related scam targeting Coinbase users. The nameservers phoenix.ns.cloudflare.com and yahir.ns.cloudflare.com are both Cloudflare‑controlled, indicating the attacker leveraged Cloudflare’s DNS services to hide its true infrastructure. While the site is no longer reachable, the presence of the domain on multiple blocklists, the detection count on VirusTotal, and the explicit branding of Coinbase as the impersonated target suggest a deliberate brand‑impersonation campaign aimed at extracting crypto assets from unsuspecting victims.
Defenders should continue to block coinbasesupports.net at the network perimeter, add the associated IP 188.114.97.3 to deny‑list rules, and monitor for new domains that resolve to the same Cloudflare nameservers or share the same registration pattern. Threat‑intel teams should also correlate any future alerts that reference the page title "Site Under Maitenance" or the same set of blocklists, as these indicators may reappear in related campaigns.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога