Перейти до звіту про безпеку
⚠️
Цей домен було позначено як шкідливий
Системи безпеки повідомляють про виявлення: 1. Публічні списки блокувань, які повідомляють про збіг: 2. Будьте дуже обережні — не вводьте облікові дані чи особисту інформацію.
Безпека домену та аналіз загроз

safeportalcustomer-coinbase[.]com

“Google”

Загрозливий вердикт Критичний 78/100 оцінка доказів
Доступність Прикритий · доступний Доступність спостерігається за допомогою перевірок маскування
Виявлення VirusTotal: 1/92 Spamhaus DBL: DBL_PHISH Збережений список блокувань відповідає: 2 URLQuery threat systems: 1 alert Уособлення бренду: Coinbase Останній відомий активний
16.05.2026 Coinbase
Огляд звіту

safeportalcustomer-coinbase.com — Прикритий · доступний (HTTP 502). Уособлення бренду: Coinbase; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 1/92 (Fortinet); URLQuery 1 alert; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 78/100. Реєстратор: Dynadot.

Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.

Зведення доказів
КРИТИЧНИЙ
Посилання
84373D9A
Оцінка
78/100

This domain, safeportalcustomer-coinbase.com, is identified as a brand impersonation threat designed to deceive users into believing they are interacting with Coinbase, a legitimate cryptocurrency exchange platform. Brand impersonation sites like this one typically mimic the appearance and functionality of the targeted brand to harvest sensitive information, such as login credentials, two-factor authentication codes, or even directly initiate unauthorized transactions. Given the domain's association with Coinbase, users may be tricked into entering their account details, which could lead to account takeovers, financial loss, or further exploitation through social engineering tactics. The risk is particularly elevated for individuals who may not scrutinize the domain name closely or who are redirected to this site through malicious links in emails, ads, or compromised third-party platforms. Analysis of the domain's infrastructure and associated indicators provides concrete evidence of its malicious nature. The domain was registered on May 16, 2026, through Dynadot Inc, a registrar often leveraged by threat actors due to its accessibility and privacy features. It resolves to the IP address 64.89.161.118, which has been linked to other suspicious or confirmed malicious activities. The SSL certificate, issued by Let's Encrypt (R13), while providing encryption, does not validate the legitimacy of the site, as certificates from this provider are freely available and frequently abused by malicious actors. VirusTotal, a widely used threat intelligence platform, shows that 1 out of 95 security vendors has flagged this domain as malicious, a low but notable detection rate that suggests emerging or targeted threats. Additionally, the domain appears on three security blocklists, further corroborating its classification as a high-risk entity. The page title, 'Google,' is another red flag, as it may indicate an attempt to obfuscate the site's true purpose or evade detection by security tools that monitor for brand-specific keywords. If you or someone you know has visited safeportalcustomer-coinbase.com or interacted with its content, immediate action is required to mitigate potential risks. First, do not enter any personal information, login credentials, or financial details on the site. If credentials were already submitted, assume they have been compromised and change them immediately on the legitimate Coinbase platform, using a trusted device and network. Enable multi-factor authentication (MFA) if not already active, and monitor the account for any unauthorized transactions or suspicious activity. It is also advisable to scan the device used to access the site for malware, as malicious domains can sometimes deliver payloads or exploit vulnerabilities. Report the domain to Coinbase's official security team to aid in their efforts to combat brand impersonation and protect other users. Additionally, consider reporting the site to relevant cybersecurity organizations or platforms, such as the Anti-Phishing Working Group (APWG) or Google Safe Browsing, to contribute to broader threat intelligence efforts. Users should remain vigilant for follow-up phishing attempts, as threat actors may use harvested information to launch further attacks via email, SMS, or phone calls.

VirusTotal
VirusTotal
1 det.
URLQuery
URLQuery
1 threat alert
URLScan
URLScan
Сертифікат TLS
Let's Encrypt
Вік
3 mo
Зафіксований статус
Прикритий · доступний 502
PhishDestroy
DestroyList
У списку
Обсяг даних VirusTotal 1 / 92 URLQuery 1 threat-system alert PhishStats checked — no match recorded OTX no community references CF Radar scan completed URLScan capture збережений звіт URLScan verdict Аналіз завершено Блокування DNS не перевірено TLS valid certificate, 87d WHOIS 3 mo old Знімок екрана 3 captures · 3 sources Ланцюжок перенаправлень не досліджено
Розвіддані з мережевої безпеки
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
DNS4EU safeportalcustomer-coinbase.com malicious Sinkholed

Процес реагування на загрози Pipeline

Відкриття
Checks
Reports
Доступність
11/13

Статус у публічних блоклистах

Збережений знімок

Заголовок сторінки
Google
Сертифікат TLS
Valid transport encryption · Виданий Let's Encrypt · valid for 87 days

Аналітика доменів

Домен
URLScan Verdict Аналіз завершено score 0 report ↗
Сервер / ASN gws · AS205759 Ghosty Networks LLC
Репутація IP abuse score 0/100 0 reports checked 13.07.2026
Реєстратор Dynadot US(US)
IP-адреса 64.89.161.118 LU
ГеолокаціяLU Schieren, LU
МережаAS205759 · Ghosty Networks LLC
Зворотний пошук IPviewdns.info → rapiddns.io →
РеєстраціяСтворено 16.05.2026 (92d)
Статус HTTP502 Error
Cloaking Cloaking Detected Bot redirect safe · score 4/6
transient_502: raw=transient_502; http=502; via=http_proxy
checked 17.08.2026
Elapsed Since First Report 10 days
Що ми враховуємо Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Прикритий · доступний.
Що містить кожен звіт Збережені записи вихідних звітів можуть посилатися на докази, доступні на той час, наприклад вердикти постачальників, реєстраційні дані, деталі хостингу, класифікації або знімки екрана. Ця сторінка не визначає точного доставленого корисного навантаження, квитанції, підтвердження чи дії одержувача.
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Вперше виявлено16.05.2026
IoC Extractionscanned 01.08.20260 wallet · 0 Telegram IoCs
Submitted URLhttp://safeportalcustomer-coinbase.com/
Сервери іменns2.dyna-ns.net
TLS Fingerprint
TLS Observationvalid from 14.05.2026scanned 17.05.2026
ICANN OVERSIGHT

Акредитація та контекст RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Нічого не надсилається автоматично.
Технології · 3 identified
Google Web Server
Web servers

Web server software.

en.wikipedia.org 100% впевненості
HSTS
Безпека

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

www.rfc-editor.org 100% впевненості
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org 100% впевненості
Detected via Cloudflare Radar · Wappalyzer engine
Поскаржитися на цей домен Надішліть докази та допоможіть захистити інших

Аналіз VirusTotal

1 / 92 постачальників безпеки позначили цей домен
View on VT
Last analyzed
Fortinet
Аналіз продуктивності сайту

Google PageSpeed Insights — mobile performance audit of safeportalcustomer-coinbase.com · checked May 16, 2026

86
Needs Work
Performance
FCP
2.33s
First Contentful Paint
LCP
2.37s
Largest Contentful Paint
CLS
0.023
Cumulative Layout Shift
TBT
389ms
Total Blocking Time
SI
2.33s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Докази та зовнішні звіти

Чи вплинув на вас цей сайт?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.

Європол
Знайдіть офіційний канал звітності для вашої країни ЄС
National police directory
Остерігайтеся шахраїв, які обіцяють повернути втрачені кошти! Злочинці можуть знову зв’язатися з жертвами, видаючи себе за слідчих, адвокатів або агентів із відновлення. Не сплачуйте авансових зборів і не діліться обліковими даними. Дізнайтеся більше про шахрайство у сфері відшкодування збитків →

Зверніться до місцевих органів влади

Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.

Довідник 97 країн
Чернетка за допомогою штучного інтелекту — деталі інциденту обробляються постачальником штучного інтелекту Перегляньте та подайте його самостійно

Перевірити будь-який домен

Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування

Сканувати зараз

Повідомити про фішинг

Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту

Повідомити

Потокова стрічка про загрози

Останні звіти про фішинг і помічені зміни доступності

Відстежувати

Будьте в курсі подій, дбайте про свою безпеку

Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога

Потокова стрічка про загрози Оскаржити це оголошення
HTML · IFRAME

Вбудувати цей звіт

Поділіться цією інформацією про загрози на своєму веб-сайті або в блозі

embed.html
<iframe
  src="https://phishdestroy.io/uk/embed/domain/safeportalcustomer-coinbase.com"
  title="PhishDestroy threat report for safeportalcustomer-coinbase.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Дуже щирий лист-подяка

Генератор сатиричних чернеток

Одержувач
Контекст зборів

Це сатирична чернетка. Суми зборів є оцінками; ми не стверджуємо, що вони точно стосуються цього домену.