coinvasxtension.webflow.io favicon

coinvasxtension.webflow.io

Category: Phishing

Scanned: Aug 5, 2026, 12:28 PM UTC · First seen: Aug 5, 2026 · Threat Engines: 8 / 91 · Times Scanned: 1
19 / 100 Trust Score Based on scan findings at the time of analysis
Potentially Dangerous
0 - High Risk50 - Moderate100 - No Threats
Not scanned has not been scanned yet. Hit Scan Now to check it.

Scans can take up to 5 minutes to complete. Please keep this tab open - we'll redirect you to the report when it's ready.

Failed
Scan unavailable
Scan failed
Protect yourself from potentially harmful websites
Combo Cleaner's real-time web protection module actively blocks access to scam, phishing & malware-infected websites.
★★★★★ 4.8 / 5 Recommended by PCrisk.com editors Windows · Mac · Android · iOS
Download Combo Cleaner Free scan · no signup

To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Screenshot of coinvasxtension.webflow.io Captured Aug 5, 2026
https://coinvasxtension.webflow.io
Screenshot of coinvasxtension.webflow.io
This website has been flagged as potentially harmful
Screenshot blurred for safety. Multiple security engines flagged potential threats at the time of scanning.
13 years (webflow.io)
Not Ranked - This website does not appear in the Tranco top list
Flagged by 8 of 91 engines
✓ Valid (TLS)
Cloudflare, Inc.
Toronto, Canada
cloudflare
Webflow
104.18.36.248
Domain & WHOIS Information
Registrar MarkMonitor, Inc.
Registered May 8, 2013 (webflow.io)
Expires May 8, 2028
Name Servers lamar.ns.cloudflare.com
DNSSEC Unsigned
Hosting Cloudflare, Inc.
This site is hosted on webflow.io - a free hosting platform. The WHOIS data above belongs to the platform, not to coinvasxtension.webflow.io. The actual creation date of this subdomain is unknown and could be as recent as today.
Reputation & Threat Check 91 security engines checked
8
8 of 91 engines flagged this website Flagged by 8 security vendors at the time of scanning
Not flagged Flagged
Flagged by 8 of 91 engines
Direct Threat Database Sources
View detailed engine results on VirusTotal
File Scan Summary Powered by Quttera Engine
4 files scanned
No threats
3
Low Risk
0
Medium Risk
0
High Risk
1
No threats Low Risk Medium Risk High Risk
coinvasxtension.webflow.io/# 2.2 KB Flagged: high risk
webflow.com/site/third-party-cookie-check.html 674 B No threats
d3e54v103j8qbb.cloudfront.net/js/jquery-3.5.1.min.dc5e7f18c8.js?site=65054679f53261fa63e7a0d5 87.4 KB No threats
cdn.prod.website-files.com/65054679f53261fa63e7a0d5/js/webflow.24a563ff7.js 36.5 KB No threats
Quttera flagged high risk files - is this your website?
Investigate and remove potential threats with Quttera
Remove Malware

Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.

External Links & Domains
9
External Links
1 Flagged
0
Iframes
Clean
5
Referenced Domains
1 Flagged
2
Flagged Resources
Detected
gtly.toFlagged: Generic Malicious Object
https://gtly.to/cXmkEMB70Flagged: Generic Malicious Object
https://gtly.to/cXmkEMB70Flagged: Generic Malicious Object
https://cdn.prod.website-files.com/65054679f53261fa63e7a0d5/650546b307e8a85550bf22a8_coinbase.pngNot flagged
https://cdn.prod.website-files.com/65054679f53261fa63e7a0d5/css/coinvasxtension.webflow.4d57f8b4c.cssNot flagged
https://cdn.prod.website-files.com/65054679f53261fa63e7a0d5/js/webflow.24a563ff7.jsNot flagged
https://cdn.prod.website-files.com/img/favicon.icoNot flagged
https://cdn.prod.website-files.com/img/webclip.pngNot flagged
https://d3e54v103j8qbb.cloudfront.net/js/jquery-3.5.1.min.dc5e7f18c8.js?site%3D65054679f53261fa63e7a0d5Not flagged
https://uploads-ssl.webflow.comNot flagged
https://webflow.com/site/third-party-cookie-check.htmlNot flagged
gtly.toFlagged: Generic Malicious Object
cdn.prod.website-files.comNot flagged
d3e54v103j8qbb.cloudfront.netNot flagged
uploads-ssl.webflow.comNot flagged
webflow.comNot flagged
coinvasxtension.webflow.io Overview

Description of coinvasxtension.webflow.io

coinvasxtension.webflow.io appears to be a Webflow-hosted page presenting itself as a cryptocurrency onboarding or wallet-extension landing page. The page title references "Coinbase $ Extension - Getting Started: Wallet Extension," and the screenshot shows branding, layout, and messaging associated with Coinbase, including prompts to sign in or get started with crypto services.

Based on the visible content, the page appears designed to attract users interested in cryptocurrency accounts, wallets, or browser extensions. However, it is hosted on a webflow.io subdomain rather than an official standalone corporate domain, which may indicate it is an unofficial promotional page, a temporary landing page, or a look-alike page using third-party site-building infrastructure.

The underlying webflow.io domain is long-established as a platform domain, but that age does not necessarily reflect the age or legitimacy of this specific subpage. Based on the branding and page content, the site appears to target users of a well-known cryptocurrency platform and may be attempting to imitate that brand.

Safety Assessment for coinvasxtension.webflow.io

This page shows several risk indicators at the time of this scan. It was flagged by 8 out of 91 security engines, with multiple detections describing it as phishing or malicious. In addition, the malware scan identified one flagged page element and one flagged outbound link associated with a generic malicious-object classification. The page also closely imitates the branding of a well-known cryptocurrency company while operating from a third-party webflow.io subdomain, which may indicate a look-alike or impersonation attempt.

Although some blacklist and threat-database checks were clean at the time of this scan, that does not outweigh the combination of multi-engine phishing detections, suspicious external-link findings, and the visible brand mimicry in the screenshot. The domain itself is old because it belongs to the hosting platform, but that should not be treated as reassurance for this specific hosted page.

Based on these findings, this website may pose potential risks to visitors.

Technical Description

The site uses a valid SSL/TLS certificate issued by Google Trust Services and is served through Cloudflare infrastructure at IP address 104.18.36.248, with hosting geolocated to Toronto, Canada. Nameservers are on Cloudflare, and DNSSEC appears to be unsigned. The use of HTTPS is positive for transport encryption, but it does not by itself verify the legitimacy of the page content.

From a technical-risk perspective, the more notable concern is the flagged outbound link to gtly.to and the fact that the page is hosted as a subpage on a site-building platform rather than on an official brand-owned domain. That setup may make rapid deployment of impersonation pages easier, especially when combined with copied branding and credential-collection style calls to action.

HTTP Redirect Chain
No redirects detected - direct connection to destination
Website Insights
Not Ranked
Tranco Rank
Not in Top 1M
Visitors Unknown
Category: Phishing
Rank History (30 days)
No rank data available
No cookies data available
Dispute This Score For website owners
Believe this score is inaccurate?
If you are the website owner and believe the scan results contain errors or false positives, you can submit a dispute for manual review. Our team typically responds within 1-2 business days.
You will be asked to verify your email before the dispute can be processed.
By submitting this form, you confirm that the information provided is accurate. Disputes are reviewed manually and results may take up to 48 hours to update.
One more step…
To submit your dispute for coinvasxtension.webflow.io, please click the verification link we just emailed you. Once verified, we'll review it within 1-2 business days.
This report was generated automatically and is provided for informational purposes only. Results are based on a point-in-time scan and may contain false positives or incomplete data. This does not constitute a security audit or certification. No vendor in the market can guarantee a 100% detection rate. If you believe this report is inaccurate, please submit a dispute.

Share your experience with this website. Was it safe? Did you encounter any issues?