iii[.]uevyafcnft[.]my
“Coinbase”
iii.uevyafcnft.my — Неперевірений. Уособлення бренду: Coinbase; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 14/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 92/100. Реєстратор: NameSilo.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of the domain iii.uevyafcnft.my confirms its classification as a high-risk phishing site targeting Coinbase users, with infrastructure and detection evidence supporting this verdict. The domain was registered on July 29, 2025, through NameSilo, LLC, and uses Cloudflare nameservers (byron.ns.cloudflare.com and molly.ns.cloudflare.com), a common tactic to obscure hosting details and evade takedowns. It resolves to IP 188.114.97.3, associated with AS13335 (Cloudflare, Inc.), and its SSL certificate, issued by 宝塔面板 (Baota Panel), further indicates the use of low-cost or automated hosting infrastructure often exploited by threat actors.
The page title explicitly matches the targeted brand, 'Coinbase,' and Google Safe Browsing has flagged the domain for social engineering, a designation consistent with phishing activity. Detection engines on VirusTotal have flagged the domain, with 14 of 95 security vendors identifying it as malicious, while PhishDestroy has already blocked it. The domain appears on at least one security blocklist, reinforcing its malicious classification.
As of July 23, 2026, the site is offline, though this status may change; defenders should treat the domain as compromised and maintain blocklist entries. The combination of brand impersonation, Cloudflare hosting, and detection by multiple security vendors provides concrete evidence of its fraudulent intent. Organizations should monitor for related domains using similar naming patterns or infrastructure, as threat actors frequently rotate domains to sustain campaigns.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога