distributed-signal-clustered[.]com
“Wallet Connect”
Resumen de las pruebas
Analysis of the domain distributed-signal-clustered.com reveals a confirmed brand impersonation campaign targeting WalletConnect, a cryptocurrency wallet connection service. The domain was registered on September 1, 2025, through NiceNIC International Group Co., Limited, a registrar frequently associated with high-risk domains. Infrastructure analysis indicates the site was hosted behind Cloudflare (AS13335), resolving to the IP address 172.67.157.52, located in the United States. Nameservers alex.ns.cloudflare.com and margot.ns.cloudflare.com further confirm Cloudflare’s role in the domain’s infrastructure, alongside the use of HTTP/3 and a Google Trust Services SSL certificate (WE1).
Detection metrics demonstrate elevated risk: the domain appears on two security blocklists (PhishDestroy and ScamSniffer) and is flagged by 17 of 95 security vendors on VirusTotal. AlienVault OTX includes the domain in a single threat intelligence pulse, reinforcing its classification as malicious. The page title, 'Wallet Connect,' aligns with the reported scam type—crypto scam—and the explicit brand target, WalletConnect, confirming the impersonation intent. As of the report date, the domain has been taken offline, though its prior activity and detection history warrant continued monitoring.
Defenders should treat this domain as high-risk for cryptocurrency-related fraud, particularly phishing attempts aimed at WalletConnect users. The Gridinsoft trust score of 0/100 further supports the domain’s malicious classification. While the exact content of the phishing page remains unanalyzed, the available evidence—including registrar, hosting provider, detection counts, and blocklist presence—justifies immediate blocking and investigation of related infrastructure.
Data Coverage
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 13/08/2026
9 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Estado del dominio
Accesible → Inaccesible
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
-
Estado del dominio
Inaccesible → Accesible
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.