walletyeet[.]patch-demon115[.]workers[.]dev
Pemeriksaan phishing dan keamanan walletyeet.patch-demon115.workers.dev
“1sign · One signature wallet migration”
walletyeet.patch-demon115.workers.dev — Terakhir diketahui aktif (HTTP 200). Jenis penipuan: Crypto Drainer. Ringkasan bukti: VT 4/91 (alphaMountain.ai, Chong Lua Dao, Forcepoint ThreatSeeker, Gridinsoft); URLScan no malicious verdict; GSB no flag; BL 1 (ScamSniffer); PD 82/100. Registrar: Cloudflare.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
walletyeet.patch-demon115.workers.dev is a tenant hostname on Cloudflare, not a separately registered domain. PhishDestroy first recorded this hostname on Jun 15, 2026. The stored content classification is crypto drainer. The assembled evidence scores 82/100 (high).
Two independent sources are positive: VirusTotal and ScamSniffer. VirusTotal recorded 4 detections among 91 engines: alphaMountain.ai, Chong Lua Dao, Forcepoint ThreatSeeker, Gridinsoft on Jul 28, 2026 at 02:43 UTC. ScamSniffer listed the hostname in the external-blocklist snapshot on Aug 7, 2026 at 14:20 UTC. The evidence is not unanimous. Google Safe Browsing returned no flag on Jun 15, 2026 at 04:20 UTC. URLScan completed without a malicious verdict (score 0) on Jun 15, 2026 at 10:56 UTC.
HTTP 200 was recorded on Aug 7, 2026 at 10:03 UTC. Cloudflare is the hosting platform for this tenant, not its registrar. At collection time, the hostname resolved to 188.114.96.3 on AS13335 (Cloudflare, Inc.). The recorded endpoint location is Toronto, CA. This is shared platform infrastructure; the IP and ASN are hosting context, not attribution to unrelated tenants. The stored server header is cloudflare. Captured page title: “1sign · One signature wallet migration”. The evidence archive retains 3 visual captures from PhishDestroy and URLScan. IoC extraction completed on Jul 29, 2026 at 02:00 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators. The platform TLS certificate was issued by Let's Encrypt with validity through Aug 11, 2026; checked Jun 15, 2026 at 07:00 UTC.
No target brand has been confirmed from stored page content; hostname wording alone is not treated as brand evidence. Taken together, the page content and independent findings support classifying this hostname as crypto drainer.
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Teknologi · 9 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org Keyakinan 100%React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org Keyakinan 100%Next.js is a React framework for developing single page Javascript applications.
nextjs.org Keyakinan 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Keyakinan 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Keyakinan 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Keyakinan 100%Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive