daves-pizzas[.]xyz
“$PIZZA Distribution”
daves-pizzas.xyz — Неперевірений. Уособлення бренду: Coinbase; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 12/93 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker); 1 external blocklist match (ScamSniffer); PhishDestroy score 91/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of daves-pizzas.xyz indicates a confirmed brand‑impersonation campaign targeting Coinbase users. The domain was registered on August 30, 2025 through NICENIC INTERNATIONAL GROUP CO., LIMITED and resolves to the IPv6 address 2606:4700:3032::ac43:9cf2, which is hosted by Cloudflare (AS13335) in the United States. An SSL certificate labelled WE1 is present, providing transport‑level encryption but offering no authentication of the underlying content. The site’s HTTP response is currently offline, and the page title returned during the brief live window was “$PIZZA Distribution,” a name that does not correspond to any known Coinbase service.
The campaign is classified as a crypto‑scam and explicitly impersonates the Coinbase brand, as reflected in the intelligence tag “brand target: coinbase.” Reputation services assign extremely low trust scores (Scamadviser 1/100, Gridinsoft 0/100), and the domain appears on two independent blocklists, PhishDestroy and ScamSniffer. VirusTotal analysis shows that twelve of ninety‑three scanning engines flagged the domain as malicious, reinforcing the suspicion of malicious intent. At present, no additional artefacts such as malicious payloads, credential‑stealing forms, or redirection chains have been publicly disclosed, leaving the exact content and victim‑interaction flow uncertain.
Defenders should prioritize immediate blocking of the domain and its hosting IP at network perimeter devices, update endpoint protection signatures to include the observed VirusTotal detections, and monitor for newly registered domains that share the same registrar or similar naming patterns. Continuous observation of Cloudflare‑hosted IPv6 ranges associated with this ASN is advised, as threat actors frequently leverage the same infrastructure for rapid re‑deployment.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-05 18:51:46 UTC
Криміналістичні дані
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога