woalletcaonanecct[.]gitbook[.]io
“WalletConnect - Bridge to Multi-Chain Wallets | us”
woalletcaonanecct.gitbook.io — No verificado. Suplantación de marca: Across; Tipo de estafa: Wallet/seed Phishing. Resumen de las pruebas: VirusTotal 14/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); CF Radar malicious; PhishDestroy score 92/100. Registrador: Cloudflare.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain woalletcaonanecct.gitbook.io is currently active and is being used to impersonate the WalletConnect brand in a wallet/seed phishing campaign. The site is hosted behind Cloudflare, Inc., with authoritative nameservers dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com, and resolves to the IP address 104.18.40.47, which is located in the United States and belongs to ASN 13335 (Cloudflare). The web server presents a valid SSL certificate issued by Google Trust Services (WE1) and negotiates HTTP/3, returning an HTTP 307 redirect response. The page title returned by the server is "WalletConnect - Bridge to Multi-Chain Wallets | us," suggesting a deliberate attempt to mimic the legitimate WalletConnect service.
VirusTotal analysis shows that 16 of 95 security vendors have flagged the domain as malicious, and the domain appears on one public security blocklist. It is also listed as blocked by PhishDestroy. Independent reputation scoring (Gridinsoft) assigns a trust score of 0 out of 100, reinforcing the malicious assessment. The domain was originally registered on March 30, 2014, indicating that the infrastructure has been retained for an extended period despite the recent activity.
While the observed metadata confirms the presence of brand‑impersonating infrastructure, the exact content served to victims has not been publicly disclosed, leaving the specific phishing workflow uncertain. Defenders should treat any traffic to woalletcaonanecct.gitbook.io as hostile: block the domain at perimeter firewalls and DNS resolvers, add the IP address 104.18.40.47 to deny lists, and enforce URL filtering that matches the observed page title. Continuous monitoring of Cloudflare‑hosted assets for similar patterns is advised, as the provider may host both legitimate and malicious sites.
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % de confianzaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % de confianzaAnálisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.