koinbay-login[.]net
koinbay-login.net — 内容不可用. 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 3/93 (CRDF, Fortinet, Gridinsoft); PhishDestroy score 65/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of koinbay-login.net indicates that the domain was registered on 21 February 2026 and is currently taken offline. The site was identified as a credential phishing operation and has been blocked by the PhishDestroy network. Reputation services assign it extremely low trust scores, with Scamadviser reporting a 1 out of 100 rating and Gridinsoft a 0 out of 100 rating. The domain appears on a single security blocklist, and VirusTotal scans show that three of ninety‑three antivirus engines flagged the domain as malicious.
No additional infrastructure data such as registrar, ASN, hosting IP, or SSL certificate details are available in the current intelligence set, limiting the depth of the technical profiling. The limited detection footprint suggests a short‑lived campaign that was likely abandoned or taken down shortly after deployment. Defenders should ensure that the domain is added to local deny lists and that any outbound connections to it are blocked at the perimeter. Monitoring for newly registered domains that share the “koinbay‑login” naming pattern or that exhibit similar low‑trust scores may help to pre‑empt replication of this campaign.
Because the site is offline, active probing is not possible; however, historical DNS resolution data should be reviewed for any residual IP addresses that may have been used by the operator. Continuous ingestion of threat‑intel feeds that reference the three VirusTotal detections will aid in correlation with other observed malicious activity. In summary, koinbay-login.net represents a confirmed credential phishing vector with minimal but concrete indicators of compromise, and immediate blocking is recommended.
威胁响应 Pipeline
公共封禁名单状态
域名情报
技术细节DNS、SSL SAN、时间戳
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。