# a.chainlink.gu.cc — SUSPICIOUS > a.chainlink.gu.cc impersonates Chainlink to steal crypto wallet credentials. Detected with 0/95 VirusTotal flags, resolve with caution and avoid clicking. ## Summary a.chainlink.gu.cc has been flagged as an active crypto-wallet phishing domain designed to harvest private keys and seed phrases. The infrastructure mimics legitimate Chainlink services to deceive users into entering sensitive credentials, with the domain resolving to IP 165.154.199.173. This site poses an immediate threat to cryptocurrency holders and requires urgent defensive action. This domain was flagged with 0 detections on VirusTotal (0/95 engines), indicating it evades current detection signatures. It was registered through Gname.com Pte. Ltd., uses a Let's Encrypt SSL certificate, and traces back to creation on October 13, 1997. Despite its age, the domain has recently been repurposed for malicious activity and shows no presence on major blocklists yet, suggesting a stealth deployment strategy. Users are strongly advised to avoid visiting a.chainlink.gu.cc and to check browser bookmarks or typed URLs carefully. If credentials were entered, immediately transfer funds to a new wallet and revoke any exposed API permissions. Block the domain at the network level and report the site to your local cybercrime unit. Always verify URLs via official Chainlink channels before interacting. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 1997-10-13 04:00:00 - Registrar: Gname.com Pte. Ltd. - IP: 165.154.199.173 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/f5acc809-2e9a-487a-835b-5f62729bed2b - PhishDestroy: https://phishdestroy.io/domain/a.chainlink.gu.cc/ - LLM endpoint: https://phishdestroy.io/domain/a.chainlink.gu.cc/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/a.chainlink.gu.cc/ Last updated: 2026-04-01