coinvasxtension.webflow.io
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of coinvasxtension.webflow.io
coinvasxtension.webflow.io appears to be a Webflow-hosted page presenting itself as a cryptocurrency onboarding or wallet-extension landing page. The page title references "Coinbase $ Extension - Getting Started: Wallet Extension," and the screenshot shows branding, layout, and messaging associated with Coinbase, including prompts to sign in or get started with crypto services.
Based on the visible content, the page appears designed to attract users interested in cryptocurrency accounts, wallets, or browser extensions. However, it is hosted on a webflow.io subdomain rather than an official standalone corporate domain, which may indicate it is an unofficial promotional page, a temporary landing page, or a look-alike page using third-party site-building infrastructure.
The underlying webflow.io domain is long-established as a platform domain, but that age does not necessarily reflect the age or legitimacy of this specific subpage. Based on the branding and page content, the site appears to target users of a well-known cryptocurrency platform and may be attempting to imitate that brand.
Safety Assessment for coinvasxtension.webflow.io
This page shows several risk indicators at the time of this scan. It was flagged by 8 out of 91 security engines, with multiple detections describing it as phishing or malicious. In addition, the malware scan identified one flagged page element and one flagged outbound link associated with a generic malicious-object classification. The page also closely imitates the branding of a well-known cryptocurrency company while operating from a third-party webflow.io subdomain, which may indicate a look-alike or impersonation attempt.
Although some blacklist and threat-database checks were clean at the time of this scan, that does not outweigh the combination of multi-engine phishing detections, suspicious external-link findings, and the visible brand mimicry in the screenshot. The domain itself is old because it belongs to the hosting platform, but that should not be treated as reassurance for this specific hosted page.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL/TLS certificate issued by Google Trust Services and is served through Cloudflare infrastructure at IP address 104.18.36.248, with hosting geolocated to Toronto, Canada. Nameservers are on Cloudflare, and DNSSEC appears to be unsigned. The use of HTTPS is positive for transport encryption, but it does not by itself verify the legitimacy of the page content.
From a technical-risk perspective, the more notable concern is the flagged outbound link to gtly.to and the fact that the page is hosted as a subpage on a site-building platform rather than on an official brand-owned domain. That setup may make rapid deployment of impersonation pages easier, especially when combined with copied branding and credential-collection style calls to action.
Share your experience with this website. Was it safe? Did you encounter any issues?