chroome-ext-conbse[.]framer[.]ai
“Coinbase Chrome Extension â Secure Crypto Access”
chroome-ext-conbse.framer.ai — Nội dung không có sẵn. Mạo danh thương hiệu: Coinbase; Loại lừa đảo: Brand Impersonation. Tóm tắt bằng chứng: VirusTotal 15/94 (ChainPatrol, CRDF, CyRadar, ESET, Emsisoft); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Nhà đăng ký: CSC.
Phân tích chi tiết của PhishDestroy AI bên dưới được giữ bằng tiếng Anh để bảo toàn hồ sơ pháp chứng gốc.
PhishDestroy identifies chroome-ext-conbse.framer.ai as an active crypto-draining impersonation of Coinbase. This fraudulent site masquerades as the official Coinbase Chrome Extension under the misleading page title 'Coinbase Chrome Extension – Secure Crypto Access,' luring users into installing a malicious extension designed to drain cryptocurrency wallets. The domain resolves to IP 31.43.160.6 and leverages a Let's Encrypt SSL certificate to appear legitimate. Users attempting to access their crypto wallets through this domain risk unauthorized fund transfers and credential theft.
The domain chroome-ext-conbse.framer.ai was flagged on VirusTotal with a concerning 15 out of 95 detection score, indicating that traditional antivirus solutions currently do not recognize it as malicious. This domain is hosted on Framer, a website-building platform, which may have been exploited to host phishing content. The domain is still active and continues to impersonate Coinbase, one of the most targeted brands in crypto-related phishing attacks. With 0 detections and no blocklist entries, it poses a high risk to unsuspecting users who may inadvertently download the malicious extension or enter their credentials.
If you accessed chroome-ext-conbse.framer.ai or entered any information, immediately revoke access to your Coinbase account and any connected crypto wallets. Disconnect any installed browser extensions related to this domain, clear your browser cache, and run a malware scan using reputable security software. Always verify URLs and use official sources like PhishDestroy to confirm the legitimacy of web pages before entering sensitive information. Avoid downloading extensions or software from untrusted sources, and use hardware wallets or multi-factor authentication to add an extra layer of security to your crypto accounts.
Pipeline ứng phó với các mối đe dọa
Trạng thái trong danh sách chặn công khai
Công nghệ · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Phân tích của VirusTotal
Bằng chứng và các báo cáo bên ngoài
PD-20260411-699370 Recipient: abuse@framer.com Bạn có bị ảnh hưởng bởi trang web này không?
Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.
Hãy báo cáo với chính quyền địa phương
Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.
Kiểm tra bất kỳ tên miền nào
Phân tích mối đe dọa bằng cách sử dụng danh sách chặn được lưu trữ, WHOIS, DNS và bằng chứng quét công khai
Quét ngayBáo cáo lừa đảo qua email
Hãy gửi các tên miền đáng ngờ đến cơ sở dữ liệu mối đe dọa của chúng tôi — để bảo vệ cộng đồng
Báo cáoDòng tin tức về các mối đe dọa thời gian thực
Các báo cáo lừa đảo gần đây và những thay đổi về tính khả dụng được quan sát thấy
Theo dõiLuôn cập nhật thông tin, luôn an toàn
Theo dõi các mối đe dọa đang diễn ra hoặc phản đối danh sách này nếu bạn cho rằng đây là kết quả báo động sai