Fake message with fake urgency
Kicking off in 2 days, Coinbase will introduce some changes required by local regulations. Specifically, when you send crypto outside of Coinbase, we are required to ask you for the name and physical address of the recipient and the purpose of transfer. This allows us to verify that you control the Coinbase Wallet that is receiving the crypto assets, which is a requirement under the new regulations.
The scammers modus operandi:
then an intermediate WP site with geofencing
2.a if it is a crawler or security company the redirect is to BING
2.b if it is a user redirect to phishing page
3. Display phishing payload (third site)!
hxxps://t[.]com/something
hxxps://vornahirad[.]com/wp-includes/fonts/cb[.]php
hxxps://coinbase-com[.]dairatalbannan[.]net
hxxps://t[.]com/something
hxxps://ariaeipourlawoffice[.]com/wp-snapshots/cb[.]php
hxxps://coinbase-com[.]smartway-me[.]com
hxxps://t[.]com/something
hxxps://neakan[.]com/includes/cb[.]php
hxxps://coinbase-com[.]wintechengineeringuae[.]com
hxxps://t[.]co/j5ti1k4CTq
hxxps://coinbase-com[.]tamtastours[.]com
hxxps://ketnoon[.]com/pics/cb[.]php
urlscan.io - Website scanner for suspicious and malicious URLs