eth-refund[.]pro
Forensic brief
PhishDestroy identifies eth-refund.pro as a high-risk crypto drainer domain associated with wallet theft. The site posed as a legitimate portal named "Our Guild" but was used to deceive users into compromising their cryptocurrency wallets through Wallet Connect abuse tactics. This domain exploited social engineering techniques to trick victims into authorizing unauthorized transactions. Technically, eth-refund.pro resolved to IP address 91.92.242.155 and was registered via WebNIC on December 7, 2025. It was detected on multiple security blocklists and flagged by Google Safe Browsing for social engineering. AlienVault OTX found activity in one threat pulse, and VirusTotal analysis revealed detection by several security vendors. The threat leveraged a known drainer kit targeting crypto wallets, emphasizing its specialized malicious intent. Currently, eth-refund.pro has been taken offline, mitigating immediate risk. However, users should remain vigilant against similar fraudulent domains employing crypto wallet abuse. It is strongly advised to refrain from interacting with suspicious refund or guild-themed sites and to enable robust security practices such as multi-factor authentication and verified wallet connection prompts to prevent unauthorized access.
Threat response pipeline
Cloudflare Radar
VirusTotal
Google Safe Browsing
Forensic Evidence CollectionEvidence capture
Domain Intelligence
Web Commerce Communications Limited
Technical details
Public blocklist status
Technologies
Technologies · 1 identified
VirusTotal consensus
Aggregated detection across 18 security vendors.
Evidence & external reports
Were you affected by this site?
Were You Affected?
Report to your local authorities
Email template — registrar abuse
support@webnic.cc
Registrar: Web Commerce Communications Limited Case: PD-
Embed this report
About this report
About this report: eth-refund.pro
This domain security report is maintained by PhishDestroy's automated threat-intelligence pipeline. Our system continuously monitors this domain across 18 security vendors on VirusTotal and 4 public blocklists.
The site displays a page titled “Our Guild”.
eth-refund.pro has been flagged by 18 security vendors as of May 17, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.