webmail[.]498112coinbase[.]com
“Roundcube Webmail :: Willkommen bei Roundcube Webmail”
Зведення доказів
This domain, webmail.498112coinbase.com, is flagged as a brand impersonation phishing resource targeting Coinbase, a cryptocurrency exchange platform. Analysis indicates the domain was designed to mimic legitimate Coinbase webmail services, as evidenced by the page title 'Roundcube Webmail :: Willkommen bei Roundcube Webmail,' which suggests an attempt to deceive users into believing they are accessing an authentic email portal. No direct evidence of a cryptocurrency drainer kit was observed, but the presence of a Roundcube-themed login interface strongly implies credential harvesting as the primary objective. Infrastructure analysis reveals the domain was registered on March 06, 2026, a future date that may indicate falsified registration details or an error in data reporting. It resolves to the IP address 20.85.242.32, hosted on Microsoft Corporation’s AS8075 infrastructure in the United States. Detection metrics show the domain was flagged by 10 out of 95 security vendors on VirusTotal, while Google Safe Browsing (GSB) data is not explicitly listed. The domain appears on one security blocklist, and its SSL certificate is identified as R13. The registrar information is not provided in available intelligence, but the use of Microsoft-hosted infrastructure is notable for its potential to evade initial suspicion. As of the latest assessment, the domain has been taken offline, reducing immediate risk to end users. However, the infrastructure remains a potential vector for future malicious activity, particularly if the same threat actors reuse the hosting provider or IP range. Users who may have interacted with the domain are advised to reset credentials for any associated accounts, enable multi-factor authentication, and monitor for unauthorized transactions. Organizations should update blocklists to include the domain and IP address, while security teams should investigate potential lateral movement or secondary payload delivery via phishing links.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Хронологія виявлення
-
VirusTotal
0 → 10
-
Google Safe Browsing
0 → 1
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога