web-auth-coinbasx[.]webflow[.]io
“Coinbase® Extension® | Getting Started: Wallet Extension”
Quan sát đã lưu
Độ tương phản tiêu đề quan sát được
Tóm tắt bằng chứng
Analysis of web-auth-coinbasx.webflow.io indicates an elevated‑risk brand‑impersonation campaign targeting Coinbase users. The domain is hosted on Cloudflare (AS13335) and resolves to 172.64.151.8, an IP address located in the United States. DNS records show the authoritative nameservers are journey.ns.cloudflare.com and lamar.ns.cloudflare.com, consistent with the Cloudflare infrastructure. The site is secured with a Google Trust Services certificate issued under the WE1 intermediate, which does not provide any brand‑specific trust but confirms the use of a legitimate TLS provider.
The page returns an HTTP 404 status, and the only visible metadata is the title "Coinbase® Extension® | Getting Started: Wallet Extension," confirming the intent to mimic Coinbase’s browser extension onboarding flow. Registration information lists MarkMonitor, Inc. as the registrar, a service often used for legitimate brand protection, suggesting that the adversary deliberately leveraged a reputable registrar to increase perceived legitimacy. VirusTotal scans have flagged the domain in 16 of 95 security engines, and it appears on a single external blocklist that has already been ingested by PhishDestroy, which currently blocks the host. The campaign is classified as a crypto scam, implying that the adversary likely aims to harvest credentials or seed phrases for illicit fund extraction.
Defenders should update DNS and web‑filtering rules to block both the domain and its resolved IP, monitor for any outbound connections to Cloudflare edge nodes from internal clients, and enforce multi‑factor authentication for Coinbase accounts. Threat‑intel feeds should be enriched with the domain’s creation date (May 08, 2013) and the observed page title to improve detection of similarly crafted impersonation pages. Continuous re‑scanning is recommended, as the 404 response may be a temporary takedown; any future content changes should be re‑evaluated against existing detection signatures.
Data Coverage
Tình báo an ninh mạng
Pipeline ứng phó với các mối đe dọa
Phạm vi danh sách chặn
10 nguồn ngoài được giám sát · ảnh chụp lưu ngày 12/08/2026
10 nguồn ngoài được giám sát Không trùng khớp
Dòng thời gian phát hiện
-
Cloudflare Radar
Đã lưu lần quét Cloudflare Radar · Mở lần quét
-
Trạng thái tên miền
Có thể truy cập → Không thể truy cập
-
Cloudflare Radar
Đã lưu lần quét Cloudflare Radar · Mở lần quét
Công nghệ
Đã xác định 2 công nghệ có độ tin cậy cao
Phân tích của VirusTotal
Bạn có bị ảnh hưởng bởi trang web này không?
Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.
Hãy báo cáo với chính quyền địa phương
Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.
Kiểm tra bất kỳ tên miền nào
Phân tích mối đe dọa bằng cách sử dụng danh sách chặn được lưu trữ, WHOIS, DNS và bằng chứng quét công khai
Quét ngayBáo cáo lừa đảo qua email
Hãy gửi các tên miền đáng ngờ đến cơ sở dữ liệu mối đe dọa của chúng tôi — để bảo vệ cộng đồng
Báo cáoDòng tin tức về các mối đe dọa thời gian thực
Các báo cáo lừa đảo gần đây và những thay đổi về tính khả dụng được quan sát thấy
Theo dõiLuôn cập nhật thông tin, luôn an toàn
Theo dõi các mối đe dọa đang diễn ra hoặc phản đối danh sách này nếu bạn cho rằng đây là kết quả báo động sai