Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
web-dapp-protocol[.]org
“RPC Monitor — Web3 Wallet Recovery”
Resumo das evidências
PhishDestroy identifies web-dapp-protocol.org as an active crypto drainer posing as a Web3 protocol, warranting urgent investigation under our generic_phishing classification. This domain was flagged due to its suspicious infrastructure and lack of detection on leading threat intelligence platforms. Current risk remains under_investigation, but early indicators suggest it may evolve into a high-severity threat if left unaddressed. The domain employs a Let's Encrypt SSL certificate, resolving to IP 35.157.26.135, which hosts multiple uncategorized endpoints. Registered through Name.com, Inc. on March 28, 2026, it has not yet been blacklisted by major threat feeds, maintaining a 0/95 detection score on VirusTotal as of the latest scan. Technical analysis reveals several red flags aligning with crypto-draining campaigns: the domain’s recent creation timestamp, coupled with its association with blockchain terminology, suggests an attempt to lure cryptocurrency users. The IP address (35.157.26.135) hosts several uncategorized domains, increasing the likelihood of shared malicious infrastructure. The absence of detections on VirusTotal (0/95) indicates either a stealthy operation or a newly deployed threat. While no definitive brand impersonation has been confirmed, the naming convention mirrors legitimate Web3 protocols, potentially tricking users into connecting malicious wallet extensions or signing fraudulent transactions. Mitigation requires immediate network-level blocking of the domain and IP address (35.157.26.135). Users should verify URLs before interacting with Web3 protocols and avoid downloading wallet extensions from unverified sources. SOC teams are advised to hunt for related domains resolving to the same IP and monitor for sudden spikes in blockchain transaction alerts. Due to the domain’s recent registration, proactive takedown requests should be escalated to the registrar (Name.com) while maintaining heightened alertness for associated IOCs.
Instantâneo das evidências enviadas
- Enviado
- Registros do livro-razão
- 1
- ID do caso
PD-20260509-F44AE1- Título da página capturada
- RPC Monitor — Web3 Wallet Recovery & RPC Health
- Artefato PDF
- Evidência em PDF
Base jurídica
Texto completo da evidência
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | web-dapp-protocol.org |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 10/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Status do domínio
Acessível → Inacessível
-
Status do domínio
Inacessível → Acessível
-
Status do domínio
Inacessível → Acessível
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias
2 tecnologias identificadas com alta confiança
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of web-dapp-protocol.org · checked May 9, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo