stellarwallet[.]space
“Stellar Wallet | XLM Web Wallet | Stellar Lumens Online Wallet”
On 24 July 2026 the domain stellarwallet.space was observed hosting a wallet‑seed phishing page. The site resolved to the IPv4 address 62.173.139.159, which is announced by AS34300 Internet‑Cosmos LLC and geolocated to Russia. The domain’s authoritative name servers are ns7.wmrs.ru and ns8.wmrs.ru, and registration was performed through the REGRU‑RU registrar on 20 November 2025. No TLS certificate was presented, indicating the site operated over plain HTTP at the time of capture. The page title returned by the HTTP response is “Stellar Wallet | XLM Web Wallet | Stellar Lumens Online Wallet”, suggesting an attempt to lure users of the Stellar cryptocurrency ecosystem.
Gridinsoft assigned a trust score of 0 out of 100, and the domain appears on a single public blocklist. VirusTotal analysis recorded five detections out of ninety‑five scanned scanners, confirming malicious intent. The phishing campaign was also flagged by the PhishDestroy blocklist. The site is currently taken offline, and no further HTTP content is reachable. Analysis indicates that the infrastructure aligns with a typical wallet‑seed harvesting operation: a recently created domain, Russian hosting, and lack of encryption.
The limited number of VirusTotal detections and a single blocklist entry suggest the campaign had modest exposure before takedown. Defenders should continue to monitor the associated IP address and name‑server pair for any re‑use, enforce outbound filtering of connections to 62.173.139.159, and add stellarwallet.space to internal blocklists. Threat‑intel feeds that ingest Gridinsoft scores, PhishDestroy listings, and VirusTotal detections can be tuned to raise alerts on similar future registrations. Because the site is offline, active probing is not possible, but periodic re‑resolution of the domain may reveal re‑hosting attempts.
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 स्रोत · 10/08/2026 को सिंक किया गया
पहचान समयरेखा
संग्रहीत अवलोकन कालानुक्रमिक क्रम में।
-
Cloudflare Radar
Cloudflare Radar: पहली बार https://radar.cloudflare.com/scan/fc72aeeb-81c7-4f2c-bf9e-a50349986b7f के रूप में देखा गया
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।