build-wallet[.]pages[.]dev
build-wallet.pages.dev 피싱 및 보안 점검
“CODE COMPILER”
build-wallet.pages.dev — 콘텐츠를 사용할 수 없음 (HTTP 502). 사기 유형: Crypto Drainer. 증거 요약: VT 0/91; URLScan no malicious verdict; GSB no flag; BL 2 (MetaMask, SEAL); PD 71/100. 등록기관: Cloudflare.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
build-wallet.pages.dev is a tenant hostname on Cloudflare, not a separately registered domain. PhishDestroy first recorded this hostname on Jun 26, 2026. The hostname uses “wallet,” a pattern consistent with a wallet lure; no target brand is confirmed from stored content. The stored content classification is crypto drainer. The assembled evidence scores 71/100 (high).
Two independent sources are positive: MetaMask and SEAL. MetaMask and SEAL listed the hostname in the external-blocklist snapshot on Aug 7, 2026 at 18:20 UTC. The evidence is not unanimous. VirusTotal recorded 0 detections among 91 engines on Jul 18, 2026 at 20:45 UTC. Google Safe Browsing returned no flag on Jun 26, 2026 at 10:46 UTC. URLScan completed without a malicious verdict (score 0) on Jun 27, 2026 at 08:13 UTC. The 0/91 VirusTotal result therefore records detection disagreement at that collection time, not the absence of the later source findings.
HTTP 502 was recorded on Aug 7, 2026 at 01:01 UTC; content was unavailable. Cloudflare is the hosting platform for this tenant, not its registrar. At collection time, the hostname resolved to 172.66.47.71 on AS13335 (CLOUDFLARENET - Cloudflare, Inc., US). The associated network metadata labels the endpoint as AS13335 Cloudflare, Inc. in San Francisco, US. This is shared platform infrastructure; the IP and ASN are hosting context, not attribution to unrelated tenants. The stored server header is cloudflare. Captured page title: “CODE COMPILER”. DOM analysis completed on Jun 26, 2026 at 14:20 UTC; stored DOM score 0/100. The evidence archive retains 2 visual captures from PhishDestroy and URLScan. IoC extraction completed on Jul 29, 2026 at 02:51 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
No target brand has been confirmed from stored page content; hostname wording alone is not treated as brand evidence. The 0/100 DOM score means that the DOM pass stored no scored indicators; it does not negate the independent source findings. Taken together, the page content and independent findings support classifying this hostname as crypto drainer.
위협 대응 Pipeline
공개 차단 목록 상태
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.