webextension[.]wixstudio[.]com
webextension.wixstudio.com 피싱 및 보안 점검
“Coinbase Wallet Extension: How to Connect It to Your Browser”
webextension.wixstudio.com — 콘텐츠를 사용할 수 없음 (HTTP 404). 사기 유형: Generic Phishing. 증거 요약: VirusTotal 8/94 (ChainPatrol, alphaMountain.ai, Cluster25, CRDF, CyRadar); URLQuery 2 alerts; PhishDestroy score 74/100. 등록기관: GoDaddy.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
PhishDestroy identifies webextension.wixstudio.com (seed 2fb80b) as an active crypto drainer site masquerading as a legitimate WebExtension download portal. The threat actor employs a lure page mimicking browser extension repositories to trick users into downloading malicious packages that drain cryptocurrency wallets upon installation. No direct brand impersonation of major browsers was detected, indicating a standalone crypto-drainer operation rather than a supply-chain attack leveraging Chrome or Firefox branding. The domain does not host a known drainer kit fingerprint (e.g., MetaMask or WalletConnect forgeries), but its infrastructure is consistent with automated crypto-scams that auto-deploy wallet-draining JavaScript payloads upon interaction.
This domain was flagged by PhishDestroy with the following technical indicators: it scored 2 out of 95 detections on VirusTotal, is registered under an unknown registrar, resolves to IPv4 address 34.144.206.118, and holds a valid Let's Encrypt SSL certificate. The domain is hosted on Google Cloud (IP block owned by Google LLC) and has been active since at least March 2024. It appears on two independent real-time blocklists and is currently blocked by SEAL and MetaMask security filters. Its Google Safe Browsing (GSB) status remains unlisted as of the latest scan, suggesting either evasion or delayed categorization by GSB crawlers.
As of today, webextension.wixstudio.com remains active and responsive, serving a fraudulent WebExtension download page to visitors. Immediate takedown remains unlikely due to the abuse of legitimate cloud hosting (Google Cloud) and rapid domain cycling tactics. Users should avoid visiting the site entirely. If accidentally accessed, do not download or install any browser extension offered. Ensure your wallet extensions (e.g., MetaMask) are updated and use hardware wallet protection for high-value assets. Report the domain to your antivirus vendor and browser security teams to accelerate blocklisting. Remaining risk is elevated due to the domain’s active status and use of HTTPS to appear legitimate, despite low VirusTotal detection rates.
네트워크 보안 인텔리전스
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
ICANN OVERSIGHT
Registration: wixstudio.com
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For the registrable domain wixstudio.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of webextension.wixstudio.com · checked Apr 10, 2026
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.