shibar[.]eu
“REWARD Portal v2 | Latest Web3 Wallets”
Observación almacenada
Contraste de títulos observado
Resumen de las pruebas
On July 23, 2026 the domain shibar.eu was observed hosting a malicious page that claims to be a “REWARD Portal v2 | Latest Web3 Wallets”. The page title explicitly references Web3 wallets and aligns with the declared impersonation of the Trust Wallet brand. Technical analysis shows the domain resolves to IP address 209.94.90.1, which is located in the United States and is announced by ASN 40680 belonging to Protocol Labs. The hosting infrastructure is fronted by Cloudflare, with nameservers betty.ns.cloudflare.com and javon.ns.cloudflare.com, and the service is reachable over HTTP/3. The TLS certificate is issued by Google Trust Services under the WE1 certificate authority, confirming the use of a legitimate Certificate Authority but offering no legitimacy to the content.
An HTTP request to the root URL returns a 403 status code, indicating that direct access is denied, yet the malicious content was still indexed by security tools. VirusTotal scans recorded 14 detections out of 95 scanning engines, confirming a notable threat presence. The domain appears on one public blocklist and is specifically listed by the PhishDestroy blocking service. AlienVault OTX references the domain in a single threat‑intelligence pulse, further corroborating its malicious use. Registration information reveals the domain was purchased through Dynadot LLC, a registrar frequently seen in abuse cases.
The observed activity matches the “Wallet/Seed Phishing” category, aiming to harvest cryptocurrency wallet seeds from victims who believe they are interacting with a legitimate Trust Wallet service. As of the report date the domain has been taken offline, but the infrastructure components—including the Cloudflare front‑end and the IP address owned by Protocol Labs—remain active and could be repurposed for future campaigns.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 12/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Estado del dominio
Accesible → Inaccesible
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
-
Estado del dominio
Inaccesible → Accesible
Tecnologías
2 tecnologías identificadas con alta confianza
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of shibar.eu · checked Apr 23, 2026
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.