coinhld-helpp[.]framer[.]website
“Sign In to Coinbase Pro | Professional Crypto Trading Platform”
coinhld-helpp.framer.website — 内容不可用. 品牌冒充:Coinbase; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 16/95 (ChainPatrol, Criminal IP, alphaMountain.ai, CyRadar, ESET); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 95/100. 注册商: CSC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain coinhld-helpp.framer.website was registered on November 19, 2021 through CSC Corporate Domains, Inc. and is hosted on Amazon Web Services under ASN 16509 (Amazon.com, Inc.), resolving to the IPv4 address 35.71.142.77 located in the United States. The site presented a TLS certificate issued by Let’s Encrypt (E7), indicating encrypted HTTPS support, and the server responded with HTTP status 404 at the time of analysis. The page title returned by the web server was "Sign In to Coinbase Pro | Professional Crypto Trading Platform," directly referencing the Coinbase brand, confirming a brand‑impersonation intent.
Technical fingerprints show the use of Framer Sites, React, HSTS, and HTTP/3, all consistent with modern web‑hosting stacks but not indicative of malicious payloads themselves. VirusTotal scanned the domain and recorded 16 detections out of 95 security‑vendor engines, providing independent confirmation of its malicious nature. The domain appears on one public security blocklist and is explicitly listed by PhishDestroy as a blocked entry, reinforcing its classification as a crypto‑related scam.
Current operational status is offline, with the site returning 404, yet the infrastructure artifacts remain observable. Defensive recommendations include adding the domain and its associated IP address (35.71.142.77) to network blocklists, monitoring DNS queries for the listed nameservers (ns-1243.awsdns-27.org, ns-1818.awsdns-35.co.uk, ns-336.awsdns-42.com, ns-792.awsdns) to detect any future resurrection, and enforcing URL filtering rules that flag the exact page title string associated with Coinbase. Analysts should also update threat‑intel feeds with the domain’s registration details, SSL fingerprint, and the observed detection count to improve cross‑organization awareness of similar brand‑impersonation campaigns.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 4 identified
JavaScript library for building user interfaces with component-based architecture.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。