help-web-coinbaselogin[.]wstd[.]io
“Coinbase Sign In”
help-web-coinbaselogin.wstd.io — 最后已知的活跃状态 (HTTP 301). 品牌冒充:Coinbase; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 13/95 (ADMINUSLabs, ChainPatrol, Criminal IP, CyRadar, ESET); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 99/100. 注册商: NameCheap.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain help-web-coinbaselogin.wstd.io was registered on February 25, 2022 through NameCheap, Inc. and currently resolves to the IP address 104.19.164.34, which is hosted by Cloudflare, Inc. (AS13335) in the United States. DNS resolution uses the Cloudflare authoritative nameservers cosmin.ns.cloudflare.com and sandra.ns.cloudflare.com. The site presents the page title "Coinbase Sign In" and is classified as a crypto‑related scam that impersonates the Coinbase brand. A TLS certificate issued by Let’s Encrypt (identifier E8) is in place, but the HTTP response returns a 401 status code, indicating that authentication is required before any content is delivered.
Reputation scoring from Gridinsoft assigns a trust score of 0 out of 100, reflecting a high confidence of malicious intent. VirusTotal analysis shows that 13 of 95 scanning engines flag the domain as malicious, and the domain appears on a single security blocklist. PhishDestroy has already taken the site offline, and its current operational status is listed as offline. The available evidence confirms that the infrastructure leverages legitimate cloud services to obscure its origin while delivering a brand‑impersonation page targeting cryptocurrency users.
Uncertainty remains regarding the exact phishing kit or payload delivered after successful credential capture, as no page content has been publicly disclosed. Defenders should continue to block the domain at network perimeter devices, update URL filtering lists with the observed indicator set, and monitor for any resurgence of similar sub‑domains under the wstd.io namespace. Incident response teams should advise users to verify Coinbase URLs through official channels and enforce multi‑factor authentication to mitigate credential reuse risks.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。