MALICIOUS — CRITICAL
walletconnectchain[.]web[.]app
Analysis of walletconnectchain.web.app indicates a high‑risk brand‑impersonation campaign targeting WalletConnect users.
- VirusTotal
- 12/95
- Blocklists
- 4 · ScamSniffer, Polkadot
- التوفر
- المحتوى غير متوفر · HTTP 404
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
walletconnectchain.web.app — المحتوى غير متوفر (HTTP 404). انتحال العلامة التجارية: WalletConnect; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 12/95 (Criminal IP, alphaMountain.ai, BitDefender, CRDF, CyRadar); 4 external blocklist matches; CF Radar malicious; PhishDestroy score 86/100. مسجّل النطاق: Google Firebase.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
Analysis of walletconnectchain.web.app indicates a high‑risk brand‑impersonation campaign targeting WalletConnect users. The site is hosted on Google Firebase and resolves to the IP address 199.36.158.100, which belongs to Fastly, Inc. (AS54113) in the United States. An SSL certificate issued by Google Trust Services (WR4) is present, and the page title returned by the server is "Decentralized Blockchain Protocol," a generic phrase that does not reference WalletConnect but aligns with the declared crypto‑scam intent. The domain is currently offline, returning an HTTP 404 status, and has been taken down as of the report date.
VirusTotal has recorded 12 detections out of 95 security vendors, confirming that multiple scanners identify malicious behavior. The domain is listed on five security blocklists and is actively blocked by services such as PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura. The infrastructure shows HSTS and HTTP/3 support, typical of modern Firebase deployments, but no nameserver information is disclosed. The evidence demonstrates a clear attempt to impersonate the WalletConnect brand, likely to lure victims into a crypto‑related fraud.
Uncertainty remains regarding the exact payload or phishing kit used, as no page content has been captured beyond the title and HTTP status. Defenders should immediately block the domain at perimeter firewalls, DNS resolvers, and proxy filters, and add it to internal threat intelligence feeds. Continuous monitoring of the associated IP range and Fastly CDN edge nodes is advisable, as threat actors may shift to adjacent hosts. Given the existing blocklist coverage and vendor detections, inclusion of the domain in automated URL filtering rules will mitigate exposure while further forensic collection is pursued.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 3 identified
Firebase is a Google-backed application development software that enables developers to develop iOS, Android and Web apps.
firebase.google.com ثقة 100٪HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجيةIndependent lookups and source reports
“The PhishDestroy system has identified this domain as a phishing threat, flagged both by our internal parser and reported by users. We also cross-reference with public databases and other antivirus systems.”
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.