conbase-authenticated-appdashboardweb[.]duia[.]ro
“Coinbase - Sign In”
Зведення доказів
The domain conbase-authenticated-appdashboardweb.duia.ro is flagged as a Coinbase impersonation used for a crypto‑scam operation. Registration records show the domain was created on 31 August 2011 and is listed under the registrar CYBER_FOLKS S.R.L., indicating a long‑standing registration that predates the recent activity. The authoritative name servers are ns1.duiadns.net and ns2.duiadns.net, both associated with the duia.ro zone. Network analysis reveals the domain resolves to the IPv4 address 130.94.12.172, which belongs to AS154177 (LIGHT NODE LIMITED) and is geolocated in the United States. No TLS certificate is presented; the site is served over plain HTTP, a typical characteristic of fraudulent credential‑harvesting pages. The page title returned by the web server is “Coinbase – Sign In”, directly mirroring the legitimate brand’s login portal.
Reputation services provide strong evidence of malicious intent. The domain appears on a single security blocklist, where it is listed by PhishDestroy. Gridinsoft assigns a trust score of 0 out of 100, the lowest possible rating. VirusTotal reports that 14 of 93 scanners flag the domain as malicious, reinforcing the suspicion. The overall classification from the supplied intelligence is a “Crypto Scam”, confirming that the site is likely intended to capture cryptocurrency‑related credentials or to lure victims into fraudulent transactions. The current operational status is offline, which may be a temporary takedown or a shift to a different hosting location.
Defenders should continue to block the domain at perimeter firewalls, DNS filters, and proxy devices. Because the domain resolves to an IP owned by a public cloud provider, additional monitoring of the IP address for any future re‑use is advisable. Threat‑intel feeds that incorporate the registrar, name‑server, and ASN information can be enriched to catch any new domains created by the same entity.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога