coinbaseru.ru
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of coinbaseru.ru
coinbaseru.ru appears to present itself as a Russian-language website about the Coinbase cryptocurrency platform. The page title and visible content describe it as an “official” Coinbase exchange site, with login and registration prompts, promotional text about buying and selling cryptocurrency, and references to mobile app downloads and account access.
Based on the domain name, page metadata, and screenshot, the site appears designed to attract Russian-speaking users interested in cryptocurrency trading or account registration. The operator is not clearly identified in the provided scan data, and the domain is not the primary official Coinbase domain. The content and branding strongly suggest an attempt to associate the site with the Coinbase brand rather than an independently branded crypto service.
Safety Assessment for coinbaseru.ru
This domain shows multiple high-risk indicators at the time of this scan. It was flagged by 19 out of 91 security engines, with many detections describing the site as phishing or malicious. The page also closely imitates the Coinbase brand in both its domain name and on-page presentation, including claims that it is an official Coinbase site. That resemblance may indicate a look-alike website intended to capture user credentials or other sensitive information.
Additional context reinforces the concern. The site references the legitimate Coinbase domain while using a separate .ru domain that incorporates the Coinbase name, and the screenshot shows login and registration calls to action consistent with credential-harvesting lures. Although one malware scan reported no flagged files, it still associated the domain with a generic malicious-object label, and one mail-reputation blocklist listing was also present for the server IP. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate that, at the time of this scan, was set to expire on 2026-08-22. It appears to be hosted on infrastructure operated by Beget Ltd in St Petersburg, Russia, using an nginx server. DNSSEC status was reported as unknown, and the nameservers point to Beget-operated DNS.
The page structure and flagged URLs suggest a WordPress-based setup, with standard WordPress paths such as /wp-json/, /xmlrpc.php, theme assets, and uploaded branding images. The use of a valid certificate does not by itself establish legitimacy, and in this case the stronger concern is the apparent brand imitation combined with multi-engine phishing detections.
Share your experience with this website. Was it safe? Did you encounter any issues?