conbasesupport[.]netlify[.]app
“Conbase Support | Learn About Cryptocurrency & Blockchain”
证据摘要
The domain conbasesupport.netlify.app is presently offline, returning an HTTP 404 status, but its historical footprint reveals a clear pattern of brand impersonation targeting Coinbase users. Infrastructure analysis shows the domain resolves to the IPv6 address 2a05:d014:58f:6200::259, which is hosted within the Amazon.com, Inc. network (AS16509) and geolocated to Germany. Registration was performed through Netlify, and the site leveraged Netlify’s hosting platform, as indicated by the detected Netlify technology stack and the presence of HTTP Strict Transport Security (HSTS). The TLS certificate in use was issued by DigiCert Inc, specifically the DigiCert Global G2 TLS RSA SHA256 2020 CA1 certificate, confirming a valid SSL chain at the time of observation.
The page title retrieved from the site, "Conbase Support | Learn About Cryptocurrency & Blockchain," mirrors the legitimate Coinbase brand and suggests an attempt to lure users seeking support for cryptocurrency services. VirusTotal scans flagged the domain by two of ninety‑five security vendors, and the site is listed on a single security blocklist, reflecting limited but notable detection. Additionally, the domain has been actively blocked by the PhishDestroy community, further corroborating its malicious intent.
While the site is no longer serving content, defenders should retain the associated indicators—IPv6 address, Netlify hosting identifiers, SSL certificate details, and the exact page title—to enrich threat intelligence feeds and enable proactive blocking. Network defenders should ensure that outbound connections to the resolved IP address are denied, monitor for any future re‑registration of similar Netlify‑hosted subdomains, and incorporate the domain name into URL filtering policies. Continuous verification against reputation services is advised, as the low detection count may evolve if the actors reactivate the site or spawn new impersonation domains.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
检测时间线
-
域名状态
可访问 → 无法访问
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
技术
识别出 2 项高置信度技术
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控