Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@namecheap.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
freewallet[.]org
Verifica phishing e sicurezza per freewallet.org
“Freewallet | Multi-currency Online Crypto Wallet for BTC, ETH, XMR and more”
freewallet.org — Ultimo attivo conosciuto (HTTP 200). Tipo di truffa: Crypto Scam. Riepilogo delle prove: VirusTotal 1/91 (Gridinsoft); PhishDestroy score 71/100. Registrar: NameCheap.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
This domain, freewallet.org, is currently flagged as a high‑risk crypto drainer. Automated analysis on July 12 2026 identified the site as actively serving fraudulent cryptocurrency‑related content, consistent with the observed page title “Freewallet | Multi‑currency Online Crypto Wallet for BTC, ETH, XMR and more”. The classification aligns with the single vendor detection on VirusTotal (1 of 95 security engines) and the presence on the PhishDestroy blocklist. Infrastructure analysis shows the domain resolves to the IP address 172.67.212.249, which belongs to AS13335 Cloudflare, Inc., located in the United States. The domain was registered on March 06 2026 through NameCheap, Inc., and uses the Cloudflare authoritative nameservers damon.ns.cloudflare.com and marjory.ns.cloudflare.com. TLS is provided by Google Trust Services under the WE1 certificate, indicating a valid HTTPS endpoint despite the malicious intent. The site returns an HTTP 403 status code, suggesting that the malicious payload may be served conditionally or is hidden behind access controls. Gridinsoft’s trust scoring engine assigned a low confidence value of 39 out of 100, reinforcing the suspicion of abusive activity. Only one security blocklist currently lists the domain, but the active detection by PhishDestroy and the single positive VirusTotal result demonstrate that the infrastructure is already being monitored by threat‑intel feeds. Defenders should immediately block DNS resolution for freewallet.org and the associated IP 172.67.212.249 at network perimeters. Monitoring of outbound connections to the Cloudflare edge is advised, as the underlying malicious server could shift behind the same CDN. Adding the domain to internal threat‑intel feeds, sinkholing traffic, and alerting users about unsolicited crypto‑wallet invitations will reduce exposure. Continuous re‑evaluation is recommended, given the recent registration date and the potential for rapid evolution of the campaign.
Indicatori di sicurezza
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Prove archiviate
Dati e relazioni esterne
“Hello, I am writing to report that Freewallet.org has suspended my account without proper explanation and continues to withhold my funds. I have fully completed the KYC process, submitted all requested documents, and even confirmed availability for a scheduled call with their support team. However, they never initiated the call and have since gone silent. My support ticket has been ignored for several weeks. Meanwhile, they continue charging inactivity fees despite the account being blocked.”
PD-20260306-6D15D0 Recipient: abuse@namecheap.com Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo