cft[.]report
“CFT.Report — Комплексная проверка кошельков”
This domain is flagged as an elevated-risk crypto wallet drainer phishing site targeting Russian-speaking users. Analysis of the infrastructure indicates it was designed to mimic legitimate wallet verification services, likely to siphon cryptocurrency from victims under the guise of a "comprehensive wallet check." Infrastructure analysis reveals the domain cft.report was registered on March 14, 2026, through HOSTINGER operations, UAB, and resolved to the IP address 87.236.16.177. It is currently blocked by two security blocklists and flagged by 4 out of 95 security vendors on VirusTotal. The site employed PHP, Vue.js, Nginx, and third-party libraries such as Unpkg, jsDelivr, and FingerprintJS, which are commonly abused to facilitate client-side attacks. The SSL certificate was issued by Let's Encrypt, a low-friction provider often leveraged by malicious actors to lend superficial legitimacy. The page title, "CFT.Report — Комплексная проверка кошельков," directly translates to a service offering wallet verification, a known pretext for crypto drainer schemes. Mitigation against this threat type requires heightened vigilance when interacting with wallet verification prompts. Users should avoid connecting wallets to unverified platforms, particularly those advertised via unsolicited links or social engineering. Browser-based security extensions that block known malicious domains should be enabled, and wallet software should be configured to require explicit confirmation for high-risk transactions. Organizations should update blocklists to include this domain and its associated IP, while monitoring for similar infrastructure patterns, such as domains registered through the same registrar or resolving to the same hosting provider. Given the domain's current offline status, further monitoring is advised to detect potential re-emergence under a different name or IP.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | cft.report |
malicious | Sinkholed |
| DNS4EU | cft.report |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 6 identified
Server-side scripting language designed for web development.
Progressive JavaScript framework for building user interfaces.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Fast CDN for everything on npm — serves raw files from npm packages.
Free public CDN for open-source projects, serving files from npm and GitHub.
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of cft.report · checked Jun 26, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive