Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 2. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

walletsign-twhdrl8rvj[.]edgeone[.]app

“WalletSign: Securely Sign & Verify Multi-Chain Messages with Your Browser Wallet | BTC, ETH, SUI, T…”

Threat verdict High 56/100 evidence score
Availability Content unavailable Content was unavailable in the latest observation
VirusTotal detections: 2/93 URLQuery threat systems: 1 alert Brand impersonation: Sui
Jan 24, 2026 Sui 1 Report Sent
Evidence Summary
HIGH
Ref
5928F4A0
Score
56/100

The domain walletsign-twhdrl8rvj.edgeone.app is identified as a brand impersonation threat targeting users of the Sui blockchain platform. Analysis confirms this domain is designed to mimic legitimate wallet signature and verification services, specifically aiming to harvest cryptocurrency wallet credentials or private keys. The domain is currently offline, but prior activity indicates elevated risk due to its deceptive infrastructure and targeted phishing tactics. Infrastructure analysis reveals the domain was registered through MarkMonitor, Inc., a registrar commonly associated with both legitimate and malicious domains. It resolves to the IP address 43.152.26.58 and was created on February 21, 2026, suggesting a potentially short-lived or disposable operational timeline. The domain appears on one security blocklist, and VirusTotal reports that 2 of 95 security vendors flagged it as malicious. The SSL certificate is issued by DigiCert, Inc., specifically a DigiCert Secure Site OV G2 TLS CN RSA4096 SHA256 2022 CA1, which does not inherently indicate malicious intent but is often abused in phishing campaigns to lend false legitimacy. Current status indicates the domain has been taken offline, reducing immediate exposure risk. However, historical indicators suggest this was part of a larger campaign targeting cryptocurrency users. Organizations and individuals are advised to block the domain and associated IP at the network level. Users who interacted with this domain should immediately revoke any wallet permissions, transfer assets to a new secure wallet, and monitor for unauthorized transactions. Security teams should treat this domain as part of a broader threat cluster and investigate related infrastructure for similar impersonation attempts.

VirusTotal
VirusTotal
2 det.
URLQuery
URLQuery
1 threat alert
URLScan
URLScan
TLS Certificate
DigiCert Secure Site OV G2 TLS CN RSA4096 SHA256 2022 CA1
Observed status
Content unavailable
PhishDestroy
DestroyList
Listed
Reports Sent
1
Data coverage VirusTotal 2 / 93 URLQuery 1 threat-system alert PhishStats not checked OTX no community references CF Radar scan completed URLScan capture stored report URLScan verdict Analysis completed DNS blocks 14 checked — no blocks TLS valid certificate, 261d WHOIS not parsed Screenshot 3 captures · 3 sources Redirect chain not probed
Network Security Intelligence
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
Quad9 DNS walletsign-twhdrl8rvj.edgeone.app malicious Sinkholed

Threat Response Pipeline

Discovery
Checks
Reports
Availability
15/15
Sent Report Recorded
Stored sent-report record for registrar MarkMonitor, Inc., hosting provider, 1 abuse contact
as139341_abuse@aceville.net
Jan 25, 2026

Public Blocklist Status

Stored Capture

Page Title
WalletSign: Securely Sign & Verify Multi-Chain Messages with Your Browser Wallet | BTC, ETH, SUI, TRON
TLS Certificate
Valid transport encryption · Issued by DigiCert Secure Site OV G2 TLS CN RSA4096 SHA256 2022 CA1 · valid for 261 days

Domain Intelligence

Domain
URLScan Verdict Analysis completed score 0 report ↗
Server / ASN edgeone-pages · AS139341 ACE-AS-AP ACE, SG
IP Reputation abuse score 0/100 1 report checked Jun 16, 2026
Registrar (base domain) MarkMonitor US(US)
IP Address 43.152.26.58 DE
GeoDE Frankfurt am Main, DE
NetworkAS139341 · ACE
Time to First Unavailability 50 days
What we count Elapsed time from the first stored abuse report to the first observation that the content was unavailable. This does not establish the cause.
What each report contains Stored outgoing-report records may reference evidence available at the time, such as vendor verdicts, registration data, hosting details, classifications, or screenshots. This page does not infer the exact payload delivered, receipt, acknowledgement, or action by a recipient.
Technical detailsDNS, SSL SANs, timestamps
First DetectedJan 24, 2026
DOM Analysisanalyzed Jul 9, 2026score 0/100
IoC Extractionscanned Aug 2, 20260 wallet · 0 Telegram IoCs
Submitted URLhttps://walletsign-twhdrl8rvj.edgeone.app/
TLS Fingerprint
TLS Observationvalid from Nov 17, 2025scanned Mar 15, 2026
TLS SAN Domainsedgeone.app
Case ID
ICANN OVERSIGHT Registration: edgeone.app

Accreditation and RAA context

Registrar accreditation and DNS abuse obligations

For the registrable domain edgeone.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nothing is sent automatically.
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

2 / 93 security vendors flagged this domain
View on VT
Last analyzed
Seclookup
Webroot

Archived Evidence

Wayback Machine Snapshot
A historical snapshot is available for evidence review
View Archive
Site Performance Analysis

Google PageSpeed Insights — mobile performance audit of walletsign-twhdrl8rvj.edgeone.app · checked Mar 2, 2026

49
Poor
Performance
FCP
0.76s
First Contentful Paint
LCP
8.88s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
1399ms
Total Blocking Time
SI
3.42s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Evidence & External Reports

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260125-789FB8 Recipient: as139341_abuse@aceville.net
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 35.8 KB

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/walletsign-twhdrl8rvj.edgeone.app"
  title="PhishDestroy threat report for walletsign-twhdrl8rvj.edgeone.app"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

A Very Sincere Thank-You Note

Satirical draft generator

Recipient
Fee context

Satirical draft. Fee figures are estimates; exact attribution to this domain is not claimed.