coinoswallet[.]pages[.]dev
“Suspected phishing site | Cloudflare”
证据摘要
Analysis of coinoswallet.pages.dev conducted on 24 July 2026 shows that the domain was created on 21 February 2026 and is hosted behind Cloudflare’s network (AS13335). The hostname resolves to the IPv4 address 188.114.97.3, which is geolocated to the United States and belongs to Cloudflare, Inc. No TLS certificate is presented, indicating that the site operates without HTTPS encryption. The HTTP response currently returns a page titled “Suspected phishing site | Cloudflare”, and the domain status is reported as taken offline. Registry data list Cloudflare, Inc. as the registrar, consistent with the observed hosting provider.
The site has been added to four independent blocklists, including PhishDestroy, Polkadot, Enkrypt, and Codeesura, all of which categorize it as a crypto‑drainer campaign. VirusTotal records indicate that the URL was scanned by 93 AV engines, none of which raised a detection at the time of analysis; the absence of a flag does not constitute assurance of safety. The overall risk posture remains “under investigation” because the domain is actively referenced in threat‑intel feeds as a crypto‑related scam, yet the offline status limits immediate exposure. Defenders should continue to enforce deny‑list rules for the domain and the associated IP address, especially within corporate firewalls and DNS filtering solutions.
Given the lack of a valid SSL certificate, any attempt to establish a secure connection will fail, providing an additional indicator for automated blocklists. Continuous monitoring of Cloudflare‑issued subdomains is recommended, as adversaries frequently rotate prefixes within the same provider. Incident responders are advised to capture any residual network artifacts, correlate them with the 188.114.97.3 address, and apply IOC enrichment using the blocklist identifiers noted above. The evidence assembled here, anchored by seed 3b2ddc, supports proactive containment pending further forensic investigation.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月10日
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控