Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is caishendao5918@gmail.com.
The latest stored availability evidence still shows the domain reachable; 13 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
wallet-web3[.]com[.]cn
“Trezor官网 - 全球领先开源硬件冷钱包品牌|Trezor Suite安全管理数字资产”
The domain wallet-web3.com.cn was registered on August 22, 2025 by the entity 邦宁数字技术股份有限公司. DNS resolution points to the IP address 172.67.204.238, which is part of Cloudflare's network, as indicated by the authoritative nameservers benedict.ns.cloudflare.com and davina.ns.cloudflare.com. The domain is currently listed on one public security blocklist and has been explicitly blocked by the PhishDestroy threat‑intelligence feed, confirming its active malicious status as of the report date, July 27, 2026. VirusTotal analysis shows that 20 out of 91 scanned security vendors have flagged the domain, reinforcing the high confidence that the site is being used for illicit activity.
The primary threat classification supplied is a "crypto drainer," implying that the site likely attempts to steal cryptocurrency assets from unaware victims, though the exact mechanisms (e.g., malicious smart‑contract calls, credential harvesting, or malicious binaries) have not been disclosed. No additional data such as SSL certificate details, HTTP response codes, page title, or content snapshots are available, leaving the precise phishing vector and user‑experience unknown. Defensive teams should prioritize immediate containment actions: add wallet-web3.com.cn to DNS blocklists, enforce network‑level denial of traffic to the associated IP range, and monitor outbound connections for attempts to contact Cloudflare‑hosted services tied to this address.
Continuous re‑scanning with VirusTotal and other multi‑engine scanners is recommended to capture any evolution in detection rates. Logging of DNS queries for the domain and correlating with authentication logs can help identify compromised endpoints. Given the domain's recent creation date and rapid appearance on a blocklist, it is advisable to treat any inbound communications from this address as hostile and to educate users about the risk of unsolicited crypto‑related requests.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | wallet-web3.com.cn |
phishing | Phishing Block |
| DNS4EU | wallet-web3.com.cn |
malicious | Sinkholed |
| Hagezi Threat Feed | wallet-web3.com.cn |
malicious | Sinkholed |
| Cloudflare DNS | wallet-web3.com.cn |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Technologies · 4 identified
jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% confidenceCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% confidenceCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of wallet-web3.com.cn · checked Jul 27, 2026
Site Configuration Analysis
Evidence & External Reports
PD-20260727-3185D3 Recipient: caishendao5918@gmail.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive