eth-refund[.]pro
Domain Security & Threat Intelligence Report
Analyst Security Overview
AI-GeneratedThe domain eth-refund.pro operated as a phishing site targeting users of Wallet Connect, attempting to impersonate legitimate refund processes for cryptocurrency wallets. With a VirusTotal score of 18/95, this domain was identified as malicious by multiple security scanners, indicating a significant risk for potential victims.
Registered with WebNIC, this domain was relatively new, having been active for only 79 days. It was associated with a shared IP address (91.92.242.155) and appeared on four blocklists, suggesting a pattern of deceptive activities aimed at exploiting users' trust in wallet applications.
As of now, eth-refund.pro has been taken down. PhishDestroy played a key role in reporting and actioning against this domain to mitigate its impact, monitoring for any resurgence in similar threats in the future.
Threat Response Pipeline
Public Blocklist Status
Website Screenshot
Domain Intelligence
annalise.ns.cloudflare.com
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If you have interacted with this domain, entered personal information, or connected a cryptocurrency wallet — take immediate action. Below are resources to help you report the incident and protect yourself.
Report to Your Local Authorities
Select your country to see local cybercrime reporting contacts and complaint templates.
Related Domain Reports
Other Domains on 91.92.242.155
More Domains at WebNIC
Stay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive
URLScan Report