cap-t1[.]spec-connectweb3[.]tv
“GMX - kostenlose E-Mail, Cloud, Nachrichten & Freemail”
Evidence Summary
Analysis of cap-t1.spec-connectweb3.tv indicates an active phishing domain targeting Web3 authentication workflows. The domain was flagged by PhishDestroy and appears on one security blocklist as of August 3, 2026. Four out of 91 security vendors on VirusTotal detect the domain, suggesting a moderate but growing threat profile. Infrastructure analysis reveals the domain is hosted on an IP address associated with bulletproof or low-reputation hosting providers, though the exact ASN and geolocation remain unconfirmed in current intelligence.
The domain name incorporates 'spec-connectweb3', a pattern consistent with credential-harvesting schemes aimed at cryptocurrency wallet or decentralized application users. No specific phishing kit or brand impersonation beyond the Web3 context has been identified in available metadata. The SSL certificate, issued by a public certificate authority, appears valid, which may reduce user suspicion during initial access. HTTP status and page title have not been publicly analysed, leaving the exact content and redirection behavior uncertain.
Defenders should treat this domain as an elevated-risk credential theft vector and block it at DNS, proxy, and endpoint layers. Network monitoring for connections to this domain, particularly from Web3-related applications, is recommended to detect potential compromise. Further investigation into hosting infrastructure and associated domains may reveal additional attack surfaces.
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 13, 2026
10 monitored external feeds No match
Stored outcome evidence
Outcome & takedown attribution
- Outcome
redirected- Availability
reachable_redirect- Cause
http_redirect- Confidence
- 80%
- First observation
- Latest observation
Evidence SHA-256 fde38d94ac22
Detection timeline
-
First recorded
First stored value: Reachable
-
Availability
First stored value: Unknown
993d00c35140 -
Availability
Unknown → Redirected
3eae0f4bd27c -
Availability
Redirected → Unknown
83374d9d652c -
Availability
Unknown → Redirected
e3eaa275c148 -
Availability
Redirected → Unknown
7cebcfd4071c -
Availability
Unknown → Redirected
9da86453b52f -
Availability
Redirected → Unknown
ca255b61650a -
Availability
Unknown → Redirected
486222c796ae -
Availability
Redirected → Unknown
d8f7d37d7f95
Show all (7)
-
Availability
Unknown → Redirected
879e08e9057b -
Availability
Redirected → Unknown
afa49a2b04dd -
Availability
Unknown → Redirected
0c84b69b2bb0 -
Availability
Redirected → Unknown
e70d6b0bd31a -
Availability
Unknown → Redirected
0e41535ec10b -
Availability
Redirected → Unknown
6133b883d325 -
Availability
Unknown → Redirected
fde38d94ac22
Community reports
Reported by 0 community members, first seen Aug 4, 2026
- Unique reported URLs
- 1
Technologies
2 high-confidence technologies identified
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive