coinbase-lidiya.com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of coinbase-lidiya.com
The domain coinbase-lidiya.com appears to present itself as a Coinbase-related page, using the Coinbase name in both the domain and page title. Based on the screenshot, the site shows a minimal dark-themed interface asking for a "case access code" allegedly provided by a representative, which suggests it may be attempting to imitate a customer-support or account-recovery workflow associated with a cryptocurrency platform.
The domain itself does not appear to be an official Coinbase domain. The added "-lidiya" element makes it resemble a branded support or campaign subsite rather than a standard corporate property. Based on available data, the site appears to be independently registered very recently and is not associated with an established public traffic profile, which may be relevant when assessing authenticity.
Given the branding cues, page title, and cryptocurrency context, this website appears to target users of a digital asset service by requesting a code or other sensitive interaction. No clear evidence in the scan data identifies a legitimate operator for this domain.
Safety Assessment for coinbase-lidiya.com
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 21 out of 91 security engines, and a major threat database listed it for social-engineering activity. In addition, the domain closely resembles coinbase.com and may be a look-alike intended to benefit from confusion with the well-known Coinbase brand. The screenshot reinforces that concern by displaying the Coinbase name while prompting visitors to enter a confidential "case access code."
The domain is also extremely new, with a reported age of 0 days, no established traffic ranking, and additional scan context noting missing mail configuration. A malware scan further reported several JavaScript files as malicious or suspicious, although those file-level detections should be interpreted alongside the stronger phishing indicators rather than in isolation. The domain's IP address is also listed on one mail-reputation blocklist, which is a weaker signal than phishing and social-engineering detections but still adds some caution.
Taken together, the branding resemblance, multi-engine phishing consensus, social-engineering listing, and very recent registration substantially increase the likelihood of abuse. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate expiring on 2026-11-23. It appears to be served by nginx from an IP address hosted by Ghosty Networks LLC in Luxembourg, with Cloudflare nameservers configured. DNSSEC is unsigned, which is common but means DNS responses do not appear to benefit from DNSSEC validation.
From a technical-risk perspective, the most notable concerns are not the TLS setup itself but the surrounding indicators: a newly created domain, several flagged JavaScript assets under a Next.js-style static path, and infrastructure that does not appear tied to an established official Coinbase domain. Based on available scan data, the hosting and certificate configuration alone do not prove abuse, but they do not offset the stronger phishing-related findings.
Share your experience with this website. Was it safe? Did you encounter any issues?