wallet-v3[.]it[.]com
Проверка домена wallet-v3.it.com на фишинг и безопасность
“Website wallet-v3.it.com is ready. The content is to be added”
wallet-v3.it.com — Контент недоступен (HTTP 502). Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 2/91 (alphaMountain.ai, Gridinsoft); PhishDestroy score 63/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of the domain wallet-v3.it.com indicates it was operational as a crypto drainer scam prior to being taken offline on or before July 24, 2026. The domain, registered on February 21, 2026, resolved to the IP address 172.67.169.219, which is part of Cloudflare’s network (AS13335) and geolocated in the United States. At the time of assessment, the domain appeared on a single security blocklist maintained by PhishDestroy. Two of 93 security vendors on VirusTotal flagged the domain, though the specific detection rules or signatures were not disclosed in available intelligence. The SSL certificate associated with the domain was issued by WE1, a provider not typically linked to high-risk infrastructure but also not indicative of legitimacy in this context.
The page title, 'Website wallet-v3.it.com is ready. The content is to be added,' suggests the site was either in a preparatory or transitional state, potentially awaiting deployment of malicious payloads or redirection scripts. No further content analysis was conducted, as the domain was offline at the time of this report. Defenders should treat this domain as part of a broader crypto drainer campaign, particularly given its explicit classification in threat intelligence sources. The use of Cloudflare infrastructure is consistent with adversaries seeking to obfuscate origin servers or leverage distributed caching to evade takedowns.
While the domain is currently inactive, its registration remains valid, and reactivation cannot be ruled out. Network defenders are advised to monitor for DNS resolution attempts or SSL handshakes involving this domain or its associated IP. If observed, such activity should be blocked at the perimeter and logged for further investigation. Given the limited detection coverage, retrospective analysis of proxy or firewall logs may reveal previously undetected compromise attempts.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание