coinsqquuarelogin[.]webflow[.]io
coinsqquuarelogin.webflow.io — Контент недоступний. Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 13/94 (ADMINUSLabs, alphaMountain.ai, CyRadar, Emsisoft, G-Data); URLQuery 3 alerts; PhishDestroy score 94/100. Реєстратор: Webflow.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, coinsqquuarelogin.webflow.io, is being actively used to harvest cryptocurrency exchange credentials under the guise of a CoinSquare login portal. The threat actor has registered a plausible misspelling of the legitimate CoinSquare domain (coinsquare.io) to deceive users into entering their email and password, which are then exfiltrated to the attacker’s infrastructure. The landing page mimics CoinSquare’s login interface, including branding elements and SSL certificate issued by Google Trust Services, to appear legitimate. Once credentials are captured, attackers can bypass two-factor authentication or use the same passwords to access other services, leading to direct financial loss or account takeover in high-value crypto exchanges. The domain is currently hosted on Webflow’s infrastructure but resolves to IP 104.18.36.248, a Cloudflare address commonly abused by phishing campaigns. PhishDestroy’s investigation has confirmed this domain is flagged on two security blocklists (OpenPhish and OISD) and remains undetected on VirusTotal with 13 out of 95 engines flagging it as malicious as of seed 9dc981. The domain was created recently and leverages the Webflow.io subdomain to appear authentic, exploiting the platform’s trusted reputation. Despite having a valid SSL certificate, the mismatch between the domain name and the actual service (crypto login) is a common red flag. The lack of detection on VirusTotal suggests either a newly deployed campaign or one that evades signature-based detection through obfuscation or low-volume targeting. The combination of a recently registered domain, high-risk blocklist presence, and zero AV detections indicates a rapidly evolving threat with potential for significant impact. Users who have visited this site should immediately change their CoinSquare account password and enable two-factor authentication (2FA) if not already active. Do not use the same password across multiple platforms; generate unique, strong passwords for each account. Revoke any sessions or API keys tied to this login and monitor the account for unauthorized transactions or access attempts. Report the incident to CoinSquare support and consider using password manager alerts to detect future credential reuse. If you entered your credentials, enable 2FA immediately and review account activity for anomalies. This domain should be blocked at the network and DNS level to prevent further exposure.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | coinsqquuarelogin.webflow.io |
malicious | Sinkholed |
| OpenDNS | coinsqquuarelogin.webflow.io |
phishing | Phishing Block |
| DNS4EU | coinsqquuarelogin.webflow.io |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of coinsqquuarelogin.webflow.io · checked Apr 4, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога