jup[.]ag-api-wailet-connect-v2[.]com
“Access Denied”
Analysis of the domain jup.ag-api-wailet-connect-v2.com shows a recent registration (21 Feb 2026) that was subsequently taken offline. The domain resolves to 188.114.97.3, an address owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. The TLS certificate presented is identified as “WE1”, but no further certificate details are disclosed. HTTP requests return a page titled “Access Denied”, indicating that the site is no longer serving malicious content at the time of observation.
The domain is listed on a single security blocklist and has been flagged by the PhishDestroy service, confirming that at least one security provider has classified it as malicious. VirusTotal records show that the domain was examined by 93 scanning engines; none reported a detection, but the lack of positive findings does not imply safety. Intelligence attributes the activity to a brand‑impersonation campaign targeting the Jupiter brand and categorizes the operation as a crypto‑scam.
While the offline status limits immediate threat exposure, the infrastructure—public Cloudflare IP, recent registration, and blocklist presence—suggests a typical disposable‑hosting pattern used by threat actors. Defenders should continue to monitor for any re‑activation of the domain, enforce blocklist rules for the resolved IP, and apply URL filtering for the exact hostname. Additionally, threat‑intel feeds should be updated to reflect the domain’s association with Jupiter‑related crypto fraud, and any inbound traffic from the address should be scrutinized for anomalous behavior.
Threat Response Pipeline
Public Blocklist Status
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive