# modal-orbit-phase.com — MALICIOUS > modal-orbit-phase.com is flagged for high-risk phishing targeting Wallet Connect users. Avoid interaction and stay protected with PhishDestroy updates. ## Summary PhishDestroy identifies modal-orbit-phase.com as a high-risk phishing domain targeting Wallet Connect users. The domain engages in generic phishing tactics to steal sensitive information. Evidence includes registration through NiceNIC International Group, resolution to IP 104.21.38.149, and detection by 12 out of 95 VirusTotal security vendors. It also appears on two security blocklists, confirming malicious activity. Currently taken offline, modal-orbit-phase.com poses no immediate threat. Users should avoid the domain and report suspicious Wallet Connect links. Continued vigilance and use of security tools are recommended to prevent phishing exposure. ## Threat Details - Verdict: MALICIOUS - Site status: dead (HTTP 403) - Page title: Wallet Connect ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - Registrar: NiceNIC International Group Co., Limited - Country: HK - IP: 104.21.38.149 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: ["abby.ns.cloudflare.com", "joaquin.ns.cloudflare.com"] - SSL Issuer: Google Trust Services / WE1 ## Detection Status - VirusTotal: 12 vendors flagged Vendors: ["alphaMountain.ai", "BitDefender", "CyRadar", "ESET", "Forcepoint ThreatSeeker", "Fortinet", "G-Data", "Kaspersky", "Lionic", "Sophos", "VIPRE", "Webroot"] - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["PhishDestroy", "ScamSniffer"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019946c6-e9d4-7504-ab72-e7dfabcd6d7b.png - Cloudflare Radar: https://radar.cloudflare.com/scan/a484e818-0a0c-4e87-a46f-5fcfc94fca4e - PhishDestroy: https://phishdestroy.io/domain/modal-orbit-phase.com/ - LLM endpoint: https://phishdestroy.io/domain/modal-orbit-phase.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/modal-orbit-phase.com/ Last updated: 2026-03-19