wlcoinpusher2[.]com
“WL Coin Pusher”
This domain, wlcoinpusher2.com, is flagged as an active phishing site targeting users through a crypto-themed lure. Analysis indicates the domain was registered on August 27, 2025, through Dynadot LLC, a registrar frequently associated with fraudulent domains. The site resolves to 104.21.3.220, hosted on Cloudflare's network (AS13335), which is commonly used to obfuscate malicious infrastructure. The page title, 'WL Coin Pusher,' suggests an attempt to impersonate a cryptocurrency platform or service, though the exact content and mechanics of the scam remain unverified due to the lack of direct page analysis. Infrastructure review reveals the domain is protected by Cloudflare, utilizing nameservers bailey.ns.cloudflare.com and trey.ns.cloudflare.com, and employs Cloudflare Browser Insights and HTTP/3. The SSL certificate is issued by Google Trust Services (WE1), a legitimate provider, which does not mitigate the phishing risk. The domain is currently active, returning an HTTP 200 status, and has been blocked by at least one security vendor, PhishDestroy. VirusTotal reports 11 out of 95 security vendors flagging the domain as malicious, providing further evidence of its fraudulent nature. The domain's registration age, combined with its presence on a security blocklist and detection by multiple security vendors, supports the classification of high-risk phishing activity. Defenders should treat this domain as confirmed malicious and prioritize blocking it at the network and endpoint levels. Monitoring for related domains registered through the same registrar or resolving to the same IP may help identify additional threats. Given the crypto-themed branding, users should be alerted to potential credential harvesting or fraudulent transaction attempts associated with this site.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 Quellen · synchronisiert am 09.08.2026
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of wlcoinpusher2.com · checked Mar 2, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt