ScamLens
Brand Impersonation Warning

Subdomain Spoofing (coinbase.com)

Cached < 6hAnonymous (3/day)

Security Report for apac2-dev-render-s.coinbase.tools

ScamLens analyzed apac2-dev-render-s.coinbase.tools using 90+ threat intelligence sources and assigned a trust score of 34/100, classifying it as high risk.

Trust Score: 34/100

Risk Level: High Risk

This domain behaves more like an impersonation or spoofing entry point. Do not log in, pay, or call any number shown on the site before you preserve the spoofing and communication evidence.

Site Title
coinbase.tools&nbsp;-&nbsp;coinbase Resources and Information.
Site Description
coinbase.tools is your first and best source for information about coinbase. Here you will also find topics relating to issues of general interest. We hope you find what you are looking for!
enHTTPS ✓
1
Checked 1 times

Quick Answer

This domain behaves more like an impersonation or spoofing entry point. Do not log in, pay, or call any number shown on the site before you preserve the spoofing and communication evidence.

Positive Signals

  • +Google Safe Browsing: Safe
  • +Valid SSL certificate
  • +HTTPS encryption supported

Concerns

  • -Possible impersonation of coinbase.com
  • -2 security sources flagged as suspicious

Score Breakdown

Domain Reputation50
Threat Intelligence100
18/20 safeSafeBrowsing OK
Technical Security75
Valid SSLHTTPS
Community Reputation50
No community data yet

Was this assessment accurate?

0 say Safe0 say Suspicious
What do you think?
What to do next

apac2-dev-render-s.coinbase.tools looks like a phishing site

At least one trusted threat-intelligence feed flagged this domain. Treat any credential prompt as hostile.

Confidence:High
  1. Do not enter passwords or card details
    Phishing pages clone legitimate brand UIs to steal credentials. If you already entered them, change those passwords immediately on the real site.
  2. Close the tab and clear browser data for this domain
    This breaks any session cookie the page set and reduces the risk of follow-up phishing prompts.
  3. Report it so others are protected
    One community report can warn thousands of visitors. Use the button below.
Cross-check with independent scanners

Trust but verify — open this domain on unrelated security services and compare the verdict.

Sign in to run the AI risk analysis

The threat-intelligence signals below are available to everyone. The plain-language AI risk summary is generated on demand for signed-in users — sign in (free) to run it for this domain.

Threat-intelligence sources

Checked across 28 sources — 2 flagged this domain

Show source breakdown
  • safe_browsingclean
  • urlhausclean
  • cloudflare_radarclean
  • cert_transparencyclean
  • alienvault_otxclean
  • phishstatsclean
  • virustotalclean
  • ipqsclean
  • abuseipdbclean
  • securitytrailsclean
  • phishdestroyflagged
  • threatfoxclean
  • shodan_internetdbclean
  • phishtankclean
  • urlscanclean
  • rdapclean
  • maltiverseclean
  • dns_securityclean
  • wanted_domainsclean
  • darkwebclean
  • metamask_blocklistflagged
  • openphishclean
  • scam_blocklistclean
  • maltrailclean
  • crypto_scam_feedclean
  • phishing_armyclean
  • hagezi_tifclean
  • red_flag_domainsclean

ScamLens aggregates real-time signals from 90+ commercial and open-source threat-intelligence providers including Google Safe Browsing, VirusTotal, PhishTank, URLhaus, ThreatFox, Cloudflare Radar, OTX, IPQS, GoPlus, Honeypot.is, and more. A flagged signal is evidence; the absence of flags is not proof of safety. Use the signals below alongside community reports to decide.

Advanced Scan

Comprehensive data lookup across premium sources

$2.99one-time payment
  • Website history verification
  • Detailed WHOIS information
  • Reverse WHOIS association
  • Traffic rank analysis
  • Company registration check
Recommended

AI Deep Investigation

Cross-check the story, claims, and supporting evidence before you decide

$4.99one-time payment
  • Everything in Advanced Scan
  • AI website content analysis
  • AI cross-reference verification
  • Claim authenticity validation
  • Detailed report with evidence
Most Thorough

Comprehensive Investigation

Full-spectrum investigation with company deep search & social intelligence

$14.99one-time payment
  • Everything in Deep Investigation
  • AI company background search
  • Social media intelligence
  • Detailed suspicious point analysis
  • Event timeline & entity connections

This analysis is for informational purposes only and does not constitute a legal determination.

Security Sources

Google Safe Browsing
Safe
Cloudflare Radar
Safe
URLhaus (abuse.ch)Confidence: Medium
Not Listed
Certificate TransparencyConfidence: Low
Not Listed
AlienVault OTXConfidence: Low
Not Listed
PhishStatsConfidence: Low
Not Listed
VirusTotalConfidence: High
Not Listed
IPQualityScoreConfidence: Low
Not Listed
AbuseIPDBConfidence: Medium
Not Listed
SecurityTrailsConfidence: Low
Not Listed
PhishDestroyConfidence: Medium
Unsafe
ThreatFox (abuse.ch)Confidence: Low
Not Listed
Shodan InternetDBConfidence: Medium
Not Listed
PhishTankConfidence: Low
Not Listed
URLScan.ioConfidence: Medium
Not Listed
RDAP Domain RegistrationConfidence: Low
Not Listed
MaltiverseConfidence: Low
Not Listed
DNS SecurityConfidence: Medium
Not Listed
Law EnforcementConfidence: Low
Not Listed
darkwebConfidence: Low
Not Listed
MetaMask BlocklistConfidence: Medium
Unsafe
OpenPhishConfidence: Low
Not Listed
Scam Blocklist (Jarelllama)Confidence: Low
Not Listed
Maltrail (stamparm)Confidence: Low
Not Listed
Crypto Scam FeedConfidence: Low
Not Listed
Phishing ArmyConfidence: Low
Not Listed
HaGeZi Threat IntelligenceConfidence: Low
Not Listed
Red Flag DomainsConfidence: Low
Not Listed

Domain Information

DNSSEC
Disabled

SSL/TLS Certificate

Issuer
C=US, O=DigiCert Inc, OU=www.digicert.com, CN=Encryption Everywhere DV TLS CA - G2
Valid From
July 18, 2026
Valid To
October 15, 2026
Status
Valid
SAN List
apac2-dev-render-s.coinbase.tools

Server Information

IP Address
91.195.240.94
Hosting Provider
SEDO GmbH
ASN
AS47846 SEDO GmbH
Server Location
Cologne, Germany
Organization
SEDO

Related Intelligence

Technical Details (DNS / Headers / Subdomains)

DNS Records

Email Security

SPF Not ConfiguredDMARC Not Configured
TypeValue
A91.195.240.94

HTTP Security Headers

0/6
Strict-Transport-SecurityMissing
Content-Security-PolicyMissing
X-Frame-OptionsMissing
X-Content-Type-OptionsMissing
Referrer-PolicyMissing
Permissions-PolicyMissing

Channels / Subdomains

No data available

Community Reports

Log in to report and share your experience

...

Report & Take Down This Website

The results are based on multiple third-party data sources and AI models. False positives or negatives may occur. This report should not be used as the sole basis for any decision. Please verify with additional sources.

Preserve the account and payment evidence first

If you already logged in, paid, or shared data, move into the victim action plan first and then complete the formal report.

Open the action plan

For impersonation sites, the priority is not more browsing. It is evidence preservation and loss containment.

Related Security Guides

Learn more about how to protect yourself from this type of threat.

Understanding this threat

FAQ

Is apac2-dev-render-s.coinbase.tools safe to visit?

apac2-dev-render-s.coinbase.tools received a trust score of 34/100 from ScamLens, indicating several security concerns. 2 threat intelligence sources flagged this domain. Proceed with extreme caution.

Was apac2-dev-render-s.coinbase.tools flagged by any threat databases?

apac2-dev-render-s.coinbase.tools was flagged by 2 out of 30+ threat intelligence sources. Specifically flagged by: phishdestroy, metamask_blocklist. The detected threat categories include: general threat.

How old is apac2-dev-render-s.coinbase.tools?

Registration date information for apac2-dev-render-s.coinbase.tools is not publicly available through WHOIS records, which can itself be a risk indicator.

Does apac2-dev-render-s.coinbase.tools use HTTPS and have a valid SSL certificate?

apac2-dev-render-s.coinbase.tools uses an SSL certificate issued by C=US, O=DigiCert Inc, OU=www.digicert.com, CN=Encryption Everywhere DV TLS CA - G2, valid until October 15, 2026. The certificate is from a commercial certificate authority, which provides a higher level of validation.

What security headers does apac2-dev-render-s.coinbase.tools implement?

apac2-dev-render-s.coinbase.tools is missing important security headers: Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Strict-Transport-Security, Referrer-Policy, Permissions-Policy. Missing security headers can leave visitors vulnerable to cross-site scripting (XSS) and other web-based attacks.

What does the ScamLens community think about apac2-dev-render-s.coinbase.tools?

No community votes or reports have been submitted for apac2-dev-render-s.coinbase.tools yet. You can be the first to share your experience.

Where is apac2-dev-render-s.coinbase.tools hosted?

apac2-dev-render-s.coinbase.tools is hosted by SEDO GmbH in Cologne, Germany (ASN: ASAS47846 SEDO GmbH).

Is this report useful?

Use this report to warn others to stop logging in, paying, or contacting the listed support before they verify it.

Forward to your parents — they deserve to browse safely too.

Lost crypto to this scam?

We offer a paid forensic trace across 18 blockchains with sanctions screening — from $99.

See Crypto Trace

About this analysis

This report is generated from real-time data across 90+ threat intelligence sources, combined with AI analysis and community feedback.

Learn about our scoring methodology | Last analyzed: July 30, 2026

All SEDO GmbH domains