bitcoin-well-to-koinly[.]pages[.]dev
“Bitcoin Well to Koinly CSV Converter”
bitcoin-well-to-koinly.pages.dev — 未验证. 品牌冒充:Bitcoin; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 2/91 (alphaMountain.ai, Sophos); PhishDestroy score 76/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies bitcoin-well-to-koinly.pages.dev as an active brand impersonation domain targeting Bitcoin with an elevated risk profile. This fraudulent site masquerades as a legitimate cryptocurrency service to deceive users into divulging sensitive wallet credentials or initiating fraudulent transactions. The domain does not represent any official Bitcoin brand, project, or service, and no verifiable affiliation exists with Koinly or Bitcoin-related ecosystems. It is likely leveraging typosquatting and social engineering tactics to exploit trust in established names. This domain was flagged by 1 out of 95 security vendors on VirusTotal, indicating low signature-based detection despite its malicious intent. It is registered through Cloudflare, Inc., resolves to IP address 188.114.96.3, and uses a Google Trust Services SSL certificate. While the exact registration date is not publicly confirmed, its Pages.dev subdomain structure suggests recent creation. It remains unlisted in Google Safe Browsing (GSB) and has not been widely blocklisted, allowing it to evade early detection systems. As of the latest assessment, bitcoin-well-to-koinly.pages.dev remains active and accessible. PhishDestroy recommends immediate network and browser-level blocking of this domain using the IP and domain indicators. Users should exercise extreme caution when encountering links referencing Koinly, Bitcoin, or similar crypto services, especially in unsolicited emails or social media messages. The domain’s low detection ratio and use of reputable infrastructure (Cloudflare, Google Trust) increase its potential to bypass traditional filters, posing a persistent threat to cryptocurrency users seeking portfolio tracking tools. Remaining risk is elevated due to its active status and deceptive branding strategy.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of bitcoin-well-to-koinly.pages.dev · checked Mar 28, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。