web-ext-coin-pro[.]pages[.]dev
“Coinbase Chrome Extension - Secure Crypto Access™”
Збережене спостереження
Зафіксована відмінність заголовків
Зведення доказів
PhishDestroy identifies the active domain web-ext-coin-pro.pages.dev as a generic phishing host designed to harvest Web3 wallet credentials under the guise of a bogus browser extension. The page mimics legitimate crypto tools, luring victims with promises of enhanced functionality while secretly exfiltrating private keys and seed phrases. Evidence suggests a drainer kit is in use, though the exact payload remains under analysis. This campaign targets users searching for Chrome or Firefox extensions that interact with blockchain networks, with traffic likely driven by SEO poisoning and paid ads pointing to the Cloudflare Pages subdomain. The threat is categorized as credential theft with potential fund loss once wallets are compromised.
Technical indicators confirm the following: the domain resolves to IP 172.66.47.50, is registered through Cloudflare, Inc., and secured with a Google Trust Services SSL certificate. VirusTotal currently shows 1/95 detections, indicating it remains undetected by most antivirus engines. The domain is served from Cloudflare Pages, a platform often abused by threat actors for rapid deployment and bulletproof hosting. Although the creation date is not publicly available due to Cloudflare’s privacy protections, the active status and zero detections imply recent deployment. Google Safe Browsing (GSB) has not yet flagged the domain, and no public blocklists currently include it. These factors contribute to a high dwell time, increasing the risk of successful victim engagement.
The domain remains active and under investigation, with the current risk level classified as 'under_investigation.' PhishDestroy continues to monitor the host via behavioral analysis and sandbox detonation to identify new payloads or infrastructure pivots. Users are advised to avoid visiting web-ext-coin-pro.pages.dev or any related links offering 'crypto extensions.' Validate browser add-ons exclusively through official stores and verify developer credentials. Organizations should implement DNS filtering rules to block the IP 172.66.47.50 and monitor internal endpoints for outbound connections to this domain. Remaining risk is assessed as elevated due to the lack of detection coverage and ongoing operational status.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
8 зовнішніх джерел під наглядом Збігів немає
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of web-ext-coin-pro.pages.dev · checked Apr 13, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога