coinbase-nine[.]vercel[.]app
“React App”
coinbase-nine.vercel.app — 内容不可用. 品牌冒充:Coinbase; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 14 detections (engine total unavailable) (ADMINUSLabs, ChainPatrol, Criminal IP, alphaMountain.ai, BitDefender); URLQuery 1 alert; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 92/100. 注册商: Tucows.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain coinbase-nine.vercel.app was registered on February 21, 2026 through Tucows Domains Inc. and is currently listed as offline. Technical probing shows the host resolves to IP address 216.198.79.131, which belongs to Amazon.com, Inc. (AS16509) and is geolocated in the United States. The site presents a TLS certificate issued by Google Trust Services under the WR1 label, indicating that HTTPS is enforced, and the response headers include HTTP Strict Transport Security (HSTS). An HTTP request returns a 404 status code, suggesting that the original content is no longer reachable.
The page title reported by crawlers is "React App," providing no further context about the payload. Detection signals are strong: the domain appears on a single security blocklist and is explicitly blocked by PhishDestroy. Google Safe Browsing has flagged the URL for social engineering, and VirusTotal records 14 of 95 antivirus and URL scanners rating the domain as malicious. The threat classification from the intelligence set is a crypto‑related scam that impersonates the Coinbase brand, aligning with the observed brand target entry.
While the content is not presently accessible, the combination of a brand‑impersonation indicator, a crypto‑scam label, multiple vendor detections, and blocklist presence constitutes high confidence that the site was used for credential harvesting or illicit cryptocurrency activity. Defenders should continue to block the domain at perimeter filters, monitor for any resurgence of the URL, and update threat intelligence feeds with the observed indicators of compromise (IOC) – including the domain name, hosting IP, TLS certificate issuer, and the 404 response pattern. Ongoing surveillance of related Vercel‑hosted subdomains is recommended, as the infrastructure could be reused for future impersonation campaigns.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | coinbase-nine.vercel.app |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。