Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse-contact@sav.com.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
backpackwebextension[.]com
Pemeriksaan phishing dan keamanan backpackwebextension.com
“Backpack”
backpackwebextension.com — Kesalahan server (HTTP 502). Jenis penipuan: Generic Phishing. Ringkasan bukti: VirusTotal 11/91 (ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Registrar: Sav.com.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
PhishDestroy has completed a forensic investigation into the domain backpackwebextension.com, which was flagged as a generic phishing site impersonating the legitimate 'Backpack' Web3 wallet browser extension. The threat actor leveraged a spoofed domain to deceive users into downloading a malicious extension, likely designed to harvest cryptocurrency wallet credentials or drain digital assets. While no specific drainer kit artifacts were publicly disclosed, the domain's infrastructure suggests a typical phishing operation targeting users of Web3 applications.
This domain exhibited several malicious indicators during its active phase. VirusTotal analysis revealed detection by 4 out of 95 security vendors, while the domain resolved to IP address 198.251.84.236 and was registered through Sav.com, LLC on February 02, 2026. Additionally, the domain utilized a Let’s Encrypt SSL certificate to appear legitimate and was flagged by Google Safe Browsing (GSB) as well as two other blocklists. Notably, this domain was actively blocked by MetaMask and SEAL, indicating its presence on multiple threat intelligence platforms.
As of the latest assessment, backpackwebextension.com has been taken offline, reducing its immediate threat to users. Response actions by security vendors and browser extension platforms have contributed to its containment, though users are advised to remain cautious of similar impersonation attempts. The remaining risk is considered elevated due to the domain's prior visibility and the likelihood of threat actors recycling similar tactics. Users should verify the authenticity of browser extensions and wallet-related domains before interacting with them. Security teams are encouraged to monitor for any re-registration or re-activation of this domain.
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | backpackwebextension.com |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknologi · 8 identified
Popular CSS framework for responsive, mobile-first web development.
High-performance web server compatible with Apache configurations.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comFree public CDN for open-source projects, serving files from npm and GitHub.
Client-side email sending service — often used to exfiltrate form data without a server.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of backpackwebextension.com · checked Apr 20, 2026
Bukti & Laporan Eksternal
PD-20260420-D2940B Recipient: abuse-contact@sav.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive