filecedarwallet[.]online
“Freshy Search”
Evidence Summary
The domain filecedarwallet.online, created on June 01, 2026 and registered through Dynadot Inc., is currently active and classified as a high‑risk crypto drainer. Infrastructure analysis shows that the domain resolves to the IP address 104.21.67.60 and is served by Cloudflare nameservers chuck.ns.cloudflare.com and kinsley.ns.cloudflare.com. VirusTotal reports that 15 of 91 security vendors have flagged the domain as malicious, indicating a moderate level of detection across the scanning ecosystem.
Additionally, the domain appears on one external security blocklist and is explicitly blocked by the PhishDestroy service, reinforcing the assessment of malicious intent. The combined evidence of vendor detections, blocklist presence, and active blocking by PhishDestroy supports the conclusion that filecedarwallet.online is being used to illicitly drain cryptocurrency assets from unsuspecting victims. While the available data confirms the domain’s malicious categorization and basic hosting details, no public information is available regarding the specific payload, SSL certificate details, HTTP response codes, or the exact phishing page content.
Consequently, defenders should treat any interaction with the domain as hostile. Recommended mitigation steps include adding the domain to internal blocklists, updating network firewalls to deny outbound connections to 104.21.67.60, and monitoring DNS logs for queries to filecedarwallet.online. Organizations should also advise users to avoid any unsolicited communications that reference cryptocurrency wallets and to report any related incidents to their security operations center for further investigation.
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
Detection timeline
-
First recorded
First stored value: Reachable
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
3 high-confidence technologies identified
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of filecedarwallet.online · checked Aug 5, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive