MALICIOUS — CRITICAL
فحص التصيد والأمان للنطاق def999.net
def999[.]
This domain, def999.net, is actively flagged as a high-risk phishing infrastructure targeting WalletConnect, a known cryptocurrency wallet connection service.
- VirusTotal
- 10/95
- Blocklists
- 1 · ScamSniffer
- التوفر
- المحتوى غير متوفر · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
def999.net — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: WalletConnect; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 10/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Fortinet); 1 external blocklist match (ScamSniffer); PhishDestroy score 90/100. مسجّل النطاق: Domain International S….
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
This domain, def999.net, is actively flagged as a high-risk phishing infrastructure targeting WalletConnect, a known cryptocurrency wallet connection service. Registered on September 16, 2025, through Domain International Services Limited, the domain currently resolves to the IP address 188.114.96.3, which is protected by Cloudflare’s network. Analysis indicates the use of HTTP/3 and a Google Trust Services SSL certificate, suggesting an attempt to appear legitimate while leveraging modern web technologies to evade detection. The domain’s trust scores are critically low, with Gridinsoft assigning a 1/100 rating and Scamadviser a 15/100, reinforcing its classification as malicious. Infrastructure analysis reveals that def999.net is present on three security blocklists and has been flagged by 10 out of 95 security vendors in VirusTotal scans. Additional threat intelligence confirms its inclusion in 23 pulses on AlienVault OTX, further validating its association with malicious activity. The domain is explicitly blocked by at least three security tools, including ScamSniffer and PhishDestroy, which specialize in identifying phishing and fraudulent sites. Despite these indicators, the domain remains operational as of July 12, 2026, posing an ongoing risk to users. What remains uncertain is the exact content or functionality of the site, as no page title or detailed forensic analysis of the phishing kit has been provided. However, given the domain’s registration details, hosting infrastructure, and the consistent flagging by multiple security sources, it is reasonable to classify this as a deliberate impersonation of WalletConnect. Defenders should treat this domain as hostile and prioritize blocking it at the network level, particularly in environments where cryptocurrency-related services are accessed. Monitoring for related domains registered through the same provider or resolving to the same IP range may help identify additional threats in this campaign.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
نطاق تغطية البيانات14 recorded checks
مؤشرات الأمان
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
الأدلة المؤرشفة
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of def999.net · checked Jul 12, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
“I was a victim of a cryptocurrency scam on the Polygon network. A fraudulent website (def999.net) instructed me to deposit funds into their USDT “mining/staking platform.” I sent 1,056.32 USDT to the scammer's wallet: 0xE4512C8F7Be0f05A4dC26D47cE0c09F5bC26D Transaction hash (TXID): 0x5eb5e9019b84a812a8e2fce7d443d9d57d2f2d6f5fbf6a6ebeab6ce99541b60e After sending the funds, no service was provided and the website became unreachable. This is a fraudulent operation pretending to be a Po”
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.