691648coinbase[.]com
“Coinbase”
证据摘要
Analysis conducted on 22 July 2026 identifies the domain 691648coinbase.com as a newly registered cryptocurrency‑related impersonation site targeting Coinbase users. The WHOIS record shows registration on 21 February 2026. DNS resolution points to the IP address 172.67.213.114, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. The site was observed to be taken offline at the time of analysis, and the SSL certificate presented is identified as “WE1”.
The HTTP response included the page title “Coinbase”, matching the declared brand target and confirming the intent to mimic the legitimate service. VirusTotal scans recorded three detections out of ninety‑three scanners, indicating that a minority of security engines have flagged the domain as malicious. The domain appears on a single external blocklist and has been added to the PhishDestroy blocklist, reinforcing its classification as a crypto scam. While the site’s content has not been captured, the combination of brand impersonation, the “Crypto Scam” label, and the presence of a legitimate‑looking title strongly suggest an attempt to harvest credentials or funds from unsuspecting Coinbase customers.
Defenders should immediately add 691648coinbase.com to URL filtering rules, update intrusion‑prevention signatures, and monitor for any future re‑hosting of the same infrastructure. Continuous observation of the associated IP address and the Cloudflare network for similar domains is advised, as threat actors frequently rotate subdomains under the same CDN provider. Because the site is currently offline, any active exploitation is likely paused, but the infrastructure could be reactivated, so threat‑intel feeds should be refreshed regularly.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
取证情报
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控