coinsfera[.]vip
“Coinsfera â ÐезопаÑнÑй обмен USDT за налиÑнÑе”
Зведення доказів
PhishDestroy identifies coinsfera.vip as an active crypto drainer phishing domain designed to deceive users into transferring cryptocurrency under false pretenses. The site impersonates legitimate cryptocurrency services, likely offering fake gift cards, bonuses, or giveaways to lure victims into connecting wallets or sending funds directly. Once engaged, the domain may prompt users to connect their crypto wallets or enter private keys, enabling attackers to drain funds without consent. Users who interact with the site risk irreversible financial losses due to the irreversible nature of cryptocurrency transactions.
This domain was flagged by PhishDestroy based on verified intelligence. VirusTotal reports only 1 out of 95 security vendors detected the threat at the time of analysis, indicating low detection rates despite its malicious nature. The domain was registered on May 10, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar known for accommodating high-risk domains. It resolves to IP address 188.114.97.3 and holds a valid SSL certificate issued by Let’s Encrypt, which attackers often exploit to appear legitimate. These technical indicators suggest a well-prepared but stealthy operation targeting unsuspecting cryptocurrency users.
If you visited coinsfera.vip, disconnect your wallet immediately and revoke any permissions granted to suspicious domains through your wallet interface. Do not enter private keys, seed phrases, or wallet passwords on any site. Report the domain to your wallet provider and relevant cybersecurity authorities. Clear your browser cache and run a malware scan to ensure no malicious scripts remain active. Forward the URL to PhishDestroy’s abuse team for further investigation and blacklisting. Stay vigilant: legitimate crypto services never solicit wallet connections or private information via unsolicited links or pop-ups.
Data Coverage
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | coinsfera.vip |
malicious | Sinkholed |
| Hagezi Threat Feed | coinsfera.vip |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
Збережені докази результату
Результат і атрибуція блокування
- Результат
held- Доступність
unreachable- Причина
registrar_client_hold- Учасник
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- Механізм
client_hold- Упевненість
- 95%
- Перше спостереження
- Останнє спостереження
Оцінка часу недоступності
Час до недоступності: 0 hSHA-256 доказу d3c7d4c469bb
Хронологія виявлення
-
Доступність
Перше збережене значення: DNS неактивний
f93a11f87e4d -
Доступність
DNS неактивний → Невідомо
519c125ba1f5 -
Доступність
Невідомо → DNS неактивний
3e11708ee652 -
Доступність
DNS неактивний → Утримується
b36929602446 -
Доступність
Утримується → DNS неактивний
f52d526b76a1 -
Доступність
DNS неактивний → Невідомо
ab39a24deb55 -
Доступність
Невідомо → Утримується
ce21f3a7a98a -
Доступність
Утримується → Невідомо
6d0d371a7618 -
Доступність
Невідомо → DNS неактивний
6dfe9145995c -
Доступність
DNS неактивний → Утримується
fadfe844dde9
Показати всі (12)
-
Доступність
Утримується → DNS неактивний
641ed81dc4d5 -
Доступність
DNS неактивний → Невідомо
58d126c02778 -
Доступність
Невідомо → Утримується
87110f47d1cd -
Доступність
Утримується → Невідомо
7ddac4046c78 -
Доступність
Невідомо → DNS неактивний
d0b7046e8c2f -
Доступність
DNS неактивний → Утримується
d91e44ef8e9b -
Доступність
Утримується → DNS неактивний
ca9ed662b468 -
Доступність
DNS неактивний → Невідомо
7cba137b6ee3 -
Доступність
Невідомо → Утримується
50c0eb27b089 -
Доступність
Утримується → DNS неактивний
92f667ff6e00 -
Доступність
DNS неактивний → Невідомо
43b9f98b9f47 -
Доступність
Невідомо → Утримується
d3c7d4c469bb
Повідомлення спільноти
Повідомив 1 учасник спільноти; уперше помічено 15.05.2026
- Збережені повідомлення
- 1
- Унікальні URL
- 1
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології
Виявлено 4 технології з високою впевненістю
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of coinsfera.vip · checked May 15, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога