paperhanded-checker[.]pages[.]dev
“Suspected phishing site | Cloudflare”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
This domain, paperhanded-checker.pages.dev, was identified as a crypto wallet drainer phishing site designed to steal cryptocurrency assets by tricking users into connecting their wallets to malicious smart contracts. The site impersonated legitimate crypto tools, likely using social engineering tactics such as fake token airdrops or portfolio checkers to lure victims. Once a user connected their wallet, the site executed unauthorized transactions, draining funds without consent. Analysis indicates this was a high-risk operation targeting users of decentralized finance (DeFi) platforms. Technical evidence confirms the malicious nature of this domain. VirusTotal detections reached 13 out of 95 security vendors, indicating broad recognition of its phishing infrastructure. The domain was registered through Cloudflare, Inc., and created on March 29, 2026, suggesting a recently deployed operation. It appears on five security blocklists, including MetaMask and ScamSniffer, which specifically flag crypto-related threats. The site resolved to the IP address 188.114.97.3, a Cloudflare-hosted endpoint commonly used for rapid deployment of phishing pages. Additional trust scores from Scamadviser (11/100) and Gridinsoft (0/100) further validate its fraudulent intent. Users who visited paperhanded-checker.pages.dev or interacted with its content should immediately revoke any wallet connections made to the site. This can be done via wallet settings or blockchain explorers by checking and revoking suspicious smart contract approvals. Affected individuals should also transfer remaining assets to a new, secure wallet and monitor transaction histories for unauthorized activity. If funds were lost, report the incident to relevant blockchain analytics platforms and local cybercrime authorities. To prevent future exposure, users should verify domain authenticity before connecting wallets and employ browser-based security extensions that block known phishing domains.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
٦ مصادر خارجية مراقبة لا تطابق
المخطط الزمني للاكتشاف
-
VirusTotal
9 ← 13
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of paperhanded-checker.pages.dev · checked Jun 26, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب