Analysis of wallet-settings.org, created on July 28, 2026, shows that the domain is actively serving a crypto‑drainer operation. The registration record lists Fewmoretaps OU d/b/a Trustname.com as the registrar, and the domain is hosted on Cloudflare infrastructure, as indicated by the authoritative nameservers alexa.ns.cloudflare.com and kobe.ns.cloudflare.com. DNS resolution points to IP address 172.67.178.49, a Cloudflare‑owned address that provides anonymity for the underlying server.
The domain is currently listed on one security blocklist and has been blocked by the PhishDestroy feed, confirming that at least one reputable threat‑intelligence source has identified it as malicious. VirusTotal has processed the domain through 91 scanning engines; none of the engines raised a detection, but the absence of a flag does not constitute evidence of safety. No additional data such as SSL certificate details, HTTP response codes, page title, or Safe Browsing status is available in the supplied intelligence, leaving the content of the site unverified.
The risk level is marked as "under investigation" and the operational status is "active," indicating ongoing potential abuse. Defenders should treat the domain as hostile: add wallet-settings.org to URL filtering and domain‑blocking policies, consider blocking the associated IP 172.67.178.49, and monitor for any related traffic patterns. Continuous re‑evaluation is recommended as further telemetry becomes available.