MALICIOUS — CRITICAL
chefpal-app[.]pages[.]dev
This domain is flagged as a high-risk brand impersonation threat targeting SafePal, a cryptocurrency wallet provider.
- VirusTotal
- 3/91
- Blocklists
- No stored match
- Доступность
- Последний известный активный · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
chefpal-app.pages.dev — Последний известный активный (HTTP 200). Олицетворение бренда: SafePal; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 3/91 (alphaMountain.ai, Fortinet, LevelBlue); PhishDestroy score 76/100. Регистратор: Cloudflare Pages.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
This domain is flagged as a high-risk brand impersonation threat targeting SafePal, a cryptocurrency wallet provider. The site presents itself as the official SafePal Wallet portal, likely designed to harvest user credentials or facilitate unauthorized transactions. Analysis indicates the threat type aligns with crypto credential theft, a common precursor to account takeover and asset drainage. Infrastructure analysis reveals the domain chefpal-app.pages.dev was registered through Cloudflare Pages on May 06, 2026, resolving to IP address 188.114.96.3, geolocated to Cloudflare infrastructure in Canada. The SSL certificate is issued by Google Trust Services (WE1). VirusTotal detection shows 1 out of 95 security vendors flagging the domain as malicious. The page title, 'SafePal Wallet – Manage Your Crypto Portfolio Safely,' directly mimics the legitimate SafePal branding. The domain appears on one security blocklist and is currently active, with no takedown observed. Mitigation requires immediate blocking of the domain and its resolving IP (188.114.96.3) at the network perimeter. Organizations should update endpoint protection rules to detect and prevent access to chefpal-app.pages.dev. Users should be alerted to verify domain authenticity before entering credentials, particularly for crypto-related services. If credentials were entered, immediate password reset and wallet migration to a new seed phrase are recommended. Monitoring for unauthorized transactions on any linked accounts is critical.
Охват данных12 recorded checks
Процесс реагирования на угрозы
Статус в публичных блок-листах
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Анализ VirusTotal
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.