# PhishDestroy threat dossier — walletguards.site ================================================================ Fetched: 2026-04-30 22:23:42 UTC Canonical: https://phishdestroy.io/domain/walletguards.site/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 65/100 (PhishDestroy scoring — see methodology below) Scam classification: Crypto Drainer ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/94 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Fortinet ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.96.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: Ultahost, Inc. Nameservers: ["irena.ns.cloudflare.com", "nero.ns.cloudflare.com"] Registered: 2026-04-18 Page title: Crypto Wallet Drainer Script | VapeDrainer ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E7 Expires: 2026-07-16 Status: INVALID chain Fingerprint: 36339f43fd71e28eab37ce23a65460b56c0de6bc02f38d9f1c490fc6697d91c3 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-18 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-18 21:13:09 UTC (by PhishDestroy tracker) Last verified: 2026-04-27 01:40:08 UTC Neutralised: 2026-04-23 02:13:54 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019da1cb-0843-775c-a1ae-36343c0c759d/ Wayback Machine: https://web.archive.org/web/*/walletguards.site crt.sh CT logs: https://crt.sh/?q=%25.walletguards.site Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=walletguards.site AlienVault OTX: https://otx.alienvault.com/indicator/domain/walletguards.site URLhaus: https://urlhaus.abuse.ch/host/walletguards.site/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-18 21:14:09 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies walletguards.site as an active crypto drainer designed to deceive users into approving malicious blockchain transactions. This domain masquerades as a legitimate wallet protection service while covertly siphoning cryptocurrency assets from unsuspecting victims. The infrastructure relies on social engineering tactics, including spoofed security claims, to lure users into connecting their wallets and authorizing fraudulent transactions. Technical analysis confirms the domain’s malicious intent, with no legitimate use case identified beyond theft. This domain was flagged during routine threat intelligence monitoring. Current VirusTotal detections stand at 0 out of 95 scanning engines, indicating the site remains under the radar of most antivirus solutions. The domain utilizes a Let’s Encrypt SSL certificate to appear trustworthy, but its registration details reveal a recent creation date with no prior reputation. Additional telemetry suggests the domain is part of a broader campaign targeting cryptocurrency users, with shared infrastructure linked to known drainer toolkits. The absence of detections underscores the evolving nature of these threats and the need for proactive user vigilance. Users who visited walletguards.site should immediately revoke any wallet connections made through the site and transfer remaining assets to a secure, offline wallet. Disconnect the affected wallet from all dApps and browsers, then perform a full system scan using reputable security software. Report the domain to relevant authorities, such as the FBI’s IC3, Chainalysis, or local cybercrime units, and share indicators of compromise (e.g., transaction hashes, wallet addresses) to aid investigations. Enable multi-factor authentication (MFA) on all wallets and avoid interacting with unsolicited links or services claiming to offer security solutions. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 86e8d8cd8716d58e2570bc6396653641 TLS cert SHA-256: 36339f43fd71e28eab37ce23a65460b56c0de6bc02f38d9f1c490fc6697d91c3 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/walletguards.site/ JSON API: https://api.destroy.tools/v1/check?domain=walletguards.site Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io