spark[.]fi-dappv3-wailet[.]com
“fi-dappv3-wailet.com | 521: Web server is down”
spark.fi-dappv3-wailet.com — Контент недоступен. Тип мошенничества: Investment Scam. Сводка доказательств: VirusTotal 3/91 (ADMINUSLabs, Fortinet, Gridinsoft); Spamhaus DBL_PHISH; 1 external blocklist match (ScamSniffer); PhishDestroy score 71/100. Регистратор: MAT BAO.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
PhishDestroy has identified spark.fi-dappv3-wailet.com as a generic phishing domain with elevated risk, specifically designed as a crypto drainer to steal digital assets from decentralized finance users. The domain impersonates the legitimate Spark Finance protocol, tricking visitors into connecting their wallets and approving malicious transactions. At the time of analysis, the site was offline and displayed the error message 'fi-dappv3-wailet.com | 521: Web server is down', indicating the host server was unreachable.
Technical indicators reveal that the domain was created on February 21, 2026, and resolved to IP address 172.67.156.128. It was registered through MAT BAO CORPORATION and used an SSL certificate issued by Google Trust Services (WE1). VirusTotal flagged this domain with a score of 3 out of 95 security vendors, and it appeared on 2 security blocklists. Google Safe Browsing did not list the domain at the time of analysis, but the low detection rate suggests the threat may have been newly deployed or evading initial scans.
The current status of spark.fi-dappv3-wailet.com is offline, meaning the phishing site is no longer accessible. However, this does not eliminate the risk entirely, as the attackers may relaunch the domain under a new IP or registrar. Users who may have previously interacted with the site should revoke any token approvals granted and monitor their wallets for unauthorized transactions. PhishDestroy recommends blocking the domain at the network level and adding it to blocklists to prevent future access. Remaining risk is moderate, as the infrastructure could be reactivated, and users who visited the site while it was live may still be compromised.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: fi-dappv3-wailet.com
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain fi-dappv3-wailet.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание