# concavewrioukhwri31i784265i-yuhjbn5tkej.webflow.io — MALICIOUS > concavewrioukhwri31i784265i-yuhjbn5tkej[.]webflow[.]io is a confirmed phishing domain operating in the crypto space. Our automated scanners detected wallet-draining capabilities on this site. This domain has been flagged and added to global threat intelligence feeds. ## Summary Threat Overview The domain concavewrioukhwri31i784265i-yuhjbn5tkej[.]webflow[.]io has been identified as a cryptocurrency phishing website. This malicious site targets Web3 users by mimicking legitimate crypto platforms to steal wallet credentials and digital assets. Attack Analysis Phishing sites in the cryptocurrency space commonly employ wallet-draining techniques, fake token approval requests, and seed phrase harvesting to steal digital assets from unsuspecting victims. Risk Indicators - Domain registered on io TLD - Contains cryptocurrency-related keywords - Domain length: 50 characters - Unusually long domain name — a common phishing technique - Vt Detected - Gsb Flagged - Drainer Detected Protection Tips Always verify URLs before connecting your wallet. Use bookmarks for frequently visited crypto platforms. Enable transaction simulation tools to preview what you're signing. ## Threat Details - Verdict: MALICIOUS - Site status: alive (HTTP 200) - Page title: concavewrioukhwri31i784265i$%^ ## Domain Intelligence - Registered: 2026-03-11 01:07:01 - Registrar: REGISTRAR_NOT_FOUND - IP: 172.64.151.8 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: NS_NOT_FOUND - SSL Issuer: Google Trust Services / WE1 ## Detection Status - VirusTotal: 16 vendors flagged Vendors: ["ADMINUSLabs", "alphaMountain.ai", "BitDefender", "CyRadar", "DNS8", "ESET", "Emsisoft", "G-Data", "Google Safebrowsing", "Kaspersky", "Lionic", "Netcraft", "Sophos", "Trustwave", "VIPRE", "Webroot"] - Google Safe Browsing: FLAGGED - Blocklists: 1 hits Lists: ["PhishDestroy"] ## Live Page Content ### Page Text concavewrioukhwri31i784265i$%^&YUhjbn5tkejhfm,3098u124351 Email address, user id Password Thank you! Your submission has been received! Oops! Something went wrong while submitting the form. ### External Scripts - https://challenges.cloudflare.com/turnstile/v0/api.js - https://d3e54v103j8qbb.cloudfront.net/js/jquery-3.5.1.min.dc5e7f18c8.js?site=69a5938e40aa9aa0fe096784 - https://cdn.prod.website-files.com/69a5938e40aa9aa0fe096784/js/webflow.a0aa6ca1.5e040c4c6f25cfaa.js ### Form Fields - text - Pass - submit - Email ### External Links - https://webflow.com?utm_campaign=brandjs ## Evidence - Screenshot: https://i.ibb.co/nNSffwjv/c84d4e290b4b.png - Cloudflare Radar: https://radar.cloudflare.com/scan/ac75949e-ce02-4225-a865-4b870284e35c - PhishDestroy: https://phishdestroy.io/domain/concavewrioukhwri31i784265i-yuhjbn5tkej.webflow.io/ - LLM endpoint: https://phishdestroy.io/domain/concavewrioukhwri31i784265i-yuhjbn5tkej.webflow.io/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/concavewrioukhwri31i784265i-yuhjbn5tkej.webflow.io/ Last updated: 2026-03-15