learn-log-coinbase[.]pages[.]dev
learn-log-coinbase.pages.dev 网络钓鱼与安全检查
“Suspected phishing site | Cloudflare”
learn-log-coinbase.pages.dev — 可达 · 访问受限 (HTTP 403). 品牌冒充:Coinbase; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 14/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 92/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain learn-log-coinbase.pages.dev shows a high‑risk, brand‑impersonation campaign targeting Coinbase users. The site was registered on 21 February 2026 through Cloudflare, Inc., and is hosted on Cloudflare’s network (AS13335) with the IP address 188.114.96.3 located in the United States. DNS resolution uses the nameservers cosmin.ns.cloudflare.com and paige.ns.cloudflare.com. HTTP requests return a 403 status code, and the page title presented by the server is "Suspected phishing site | Cloudflare," indicating that Cloudflare’s protective page is being served, likely after the domain was taken offline. The site employed HSTS, HTTP/3, and presented a Google Trust Services / WE1 SSL certificate, which is typical for Cloudflare‑proxied domains.
Security telemetry flags the domain on one blocklist and records a Google Safe Browsing classification for social engineering. Gridinsoft assigns a trust score of 0 / 100, and VirusTotal reports 14 of 93 scanners flagging the domain as malicious. PhishDestroy has also listed the domain as blocked. The campaign is categorized as a crypto scam, and the branding cues point to an impersonation of Coinbase.
While the hosting infrastructure and certificate are legitimate Cloudflare services, the combination of blocklist presence, Safe Browsing flag, low trust score, and multiple antivirus detections confirms malicious intent. Uncertainty remains regarding the exact payload or credential‑harvesting mechanisms, as no page content beyond the Cloudflare warning is available. Defenders should add learn‑log‑coinbase.pages.dev to URL filtering and domain‑blocking policies, monitor outbound connections to the associated IP address, and update intrusion‑detection signatures to capture traffic to the identified nameservers. Continuous re‑evaluation of threat intelligence feeds is advised to capture any re‑appearance of the domain or related sub‑domains.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of learn-log-coinbase.pages.dev · checked Apr 22, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。