wallet-connect-8ffe8[.]web[.]app
“Wallet Connect”
Zusammenfassung der Beweislage
The domain wallet-connect-8ffe8.web.app was registered on 21 February 2026 through Google LLC’s Firebase service. DNS resolution points to the IPv6 address 2620:0:890::100, which belongs to AS54113 Fastly, Inc. and resolves to a United States location. The site serves a TLS certificate issued by Google Trust Services under the WR4 descriptor, indicating it is hosted on Google infrastructure. A request to the root URL returns an HTTP 404 status, and the page title reported by scanners is “Wallet Connect”. Technical fingerprints show the presence of Firebase, HTTP/3 and HTTP Strict Transport Security (HSTS). The domain is listed on a single security blocklist and has been explicitly blocked by PhishDestroy.
VirusTotal analysis records 11 of 93 scanning engines labeling the domain as malicious, consistent with its classification as a crypto‑related scam that impersonates the WalletConnect brand. The threat vector aligns with a brand‑impersonation campaign targeting WalletConnect users, though the exact payload or credential‑harvesting mechanisms have not been observed. At the time of reporting the host returns no content (HTTP 404) and the site is marked offline, which limits immediate user exposure but does not eliminate the possibility of rapid re‑deployment. No additional metadata such as WHOIS contact information beyond the registrar is publicly disclosed, and no alternative IP addresses have been observed. The presence of HSTS and HTTP/3 indicates that the actor leverages modern web protocols to improve resilience against network‑level interception.
Given the 11/93 detection rate on VirusTotal and placement on a blocklist, the confidence in the malicious classification is elevated. Security teams should add the IPv6 address and domain to block lists, enforce DNS filtering for the full hostname, and monitor for any related Firebase project identifiers.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | wallet-connect-8ffe8.web.app |
malicious | Sinkholed |
| OpenDNS | wallet-connect-8ffe8.web.app |
phishing | Phishing Block |
| DNS4EU | wallet-connect-8ffe8.web.app |
malicious | Sinkholed |
| DNS0 Zero | wallet-connect-8ffe8.web.app |
malicious | Sinkholed |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 13.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
Domainstatus
Erreichbar → Nicht erreichbar
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
Technologien
3 Technologien mit hoher Konfidenz erkannt
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of wallet-connect-8ffe8.web.app · checked Mar 2, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt