defillama-es-co[.]pages[.]dev
“Home | DeFiLlama Wallet (2025)”
defillama-es-co.pages.dev — Konten tidak tersedia. Peniruan identitas merek: Across; Jenis penipuan: Seed Phrase Theft. Ringkasan bukti: VirusTotal 11/93 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, Fortinet); Google Safe Browsing flagged; PhishDestroy score 83/100. Registrar: Cloudflare.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
The domain defillama-es-co.pages.dev was registered on February 21, 2026 and hosted on Cloudflare infrastructure, resolving to IP address 188.114.96.3 located in the United States under ASN 13335 (Cloudflare, Inc.). The site presented the page title "Home | DeFiLlama Wallet (2025)", indicating an attempt to masquerade as the legitimate DeFiLlama wallet service. TLS termination is performed by a Google Trust Services certificate (WE1), and the site enforced HSTS while supporting HTTP/3, suggesting a modern, well‑configured web server. An HTTP 403 response was observed, and the domain is currently listed as offline, yet the fingerprinted metadata remains accessible for analysis.
Reputation services flag the domain as malicious: 11 of 93 VirusTotal scanners raised alerts, Google Safe Browsing classifies it as social engineering, and a Gridinsoft trust score of 0 / 100 was recorded. The domain appears on a single security blocklist and has been actively blocked by PhishDestroy, confirming its use in wallet/seed phishing campaigns. The registration details show the domain was provisioned through Cloudflare, Inc., using the nameservers sandy.ns.cloudflare.com and dante.ns.cloudflare.com, which is consistent with the hosting provider’s automated provisioning process. While the page title provides clear evidence of brand impersonation, other content has not been publicly disclosed, leaving the exact phishing payload unknown.
Defenders should immediately block the domain at perimeter defenses, add it to threat‑intelligence feeds, and monitor for any future resolution changes that could indicate re‑use of the same infrastructure. Continuous observation of the associated IP range (188.114.96.0/24) is advisable, as Cloudflare often hosts multiple malicious actors on shared addresses. Organizations that use DeFiLlama services should educate users about the risk of unsolicited wallet links and enforce multi‑factor authentication where possible.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Intelijen Forensik
Teknologi · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of defillama-es-co.pages.dev · checked Apr 21, 2026
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive