VirusTotal
19 / 89
“Freshy Search”
The domain filecedarwallet.online, created on June 01, 2026 and registered through Dynadot Inc., is currently active and classified as a high‑risk crypto drainer. Infrastructure analysis shows that the domain resolves to the IP address 104.21.67.60 and is served by Cloudflare nameservers chuck.ns.cloudflare.com and kinsley.ns.cloudflare.com. VirusTotal reports that 15 of 91 security vendors have flagged the domain as malicious, indicating a moderate level of detection across the scanning ecosystem.
Additionally, the domain appears on one external security blocklist and is explicitly blocked by the PhishDestroy service, reinforcing the assessment of malicious intent. The combined evidence of vendor detections, blocklist presence, and active blocking by PhishDestroy supports the conclusion that filecedarwallet.online is being used to illicitly drain cryptocurrency assets from unsuspecting victims. While the available data confirms the domain’s malicious categorization and basic hosting details, no public information is available regarding the specific payload, SSL certificate details, HTTP response codes, or the exact phishing page content.
Consequently, defenders should treat any interaction with the domain as hostile. Recommended mitigation steps include adding the domain to internal blocklists, updating network firewalls to deny outbound connections to 104.21.67.60, and monitoring DNS logs for queries to filecedarwallet.online. Organizations should also advise users to avoid any unsolicited communications that reference cryptocurrency wallets and to report any related incidents to their security operations center for further investigation.
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
Scanner note: unavailable: raw=connection_error; http=0; via=http_proxy; error=SOCKSHTTPConnectionPool(host='filecedarwallet.online', port=80): Max retries exceeded with url: / (Caused by NewConnecti
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Edge-IP reputation is not attributed to this domain.
chuck.ns.cloudflare.comkinsley.ns.cloudflare.comLocation describes the IP network.
524c6d84ab082315b4ae6e42488a8b51e5d2f6ff8bbd1878d8a6bcdf91382a14Saved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of filecedarwallet.online · checked Aug 5, 2026
104.21.67.60. 11 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Select your country to get official cybercrime contacts, or create a complaint draft →.
Template-based draft · optional AI wording assistance requires separate consent
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowSubmit suspicious domains to our threat database — protect the community
ReportRecent phishing reports and observed availability changes
MonitorMonitor live threats or contest this listing if you believe it's a false positive