sso-ca-netcoins----cdn[.]webflow[.]io
“Netcoins | Login”
sso-ca-netcoins----cdn.webflow.io — Неперевірений. Уособлення бренду: Netcoins; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 18/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 3 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. Реєстратор: Webflow.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies the domain sso-ca-netcoins----cdn.webflow.io as an active phishing scam targeting cryptocurrency users by mimicking a Netcoins single sign-on portal. This domain poses an elevated risk due to its use of deceptive branding and a fraudulent login interface designed to harvest user credentials and session tokens. The threat actor leverages the trusted Webflow.io CDN subdomain and a Google Trust Services SSL certificate to lend superficial legitimacy to the phishing page, increasing the likelihood of successful deception.
This domain was flagged by 20 out of 95 VirusTotal security vendors, indicating widespread detection as malicious. It resolves to IP address 172.64.151.8, a Cloudflare infrastructure node commonly abused by threat actors for hosting phishing content. The SSL certificate issued to this domain is signed by Google Trust Services, which does not validate the legitimacy of the underlying service—only the cryptographic authenticity of the certificate itself. As a dynamically generated subdomain under webflow.io, it lacks a traditional creation date, but its current malicious status is confirmed through real-time detection feeds and active phishing reports.
Users should immediately block access to sso-ca-netcoins----cdn.webflow.io and avoid entering any login credentials or personal information. Organizations are advised to block the domain at DNS and firewall levels using threat intelligence feeds. Since this domain uses a Google-issued SSL certificate, traditional certificate pinning or SSL inspection may not detect the fraud; behavioral analysis and user awareness remain critical. Report any exposure or suspicious access to your security team or through official phishing reporting channels. The threat actor’s use of a trusted CDN and legitimate certificate underscores the need for multi-factor authentication and zero trust access policies to mitigate credential theft.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | sso-ca-netcoins----cdn.webflow.io |
malicious | Sinkholed |
| OpenDNS | sso-ca-netcoins----cdn.webflow.io |
phishing | Phishing Block |
| DNS4EU | sso-ca-netcoins----cdn.webflow.io |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 4 identified
Webflow is Software-as-a-Service (SaaS) for website building and hosting.
webflow.com 100% впевненостіjQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of sso-ca-netcoins----cdn.webflow.io · checked Apr 21, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога