walletconnectchain[.]web[.]app
“Decentralized Blockchain Protocol”
Сохранённое наблюдение
Зафиксированное различие заголовков
Сводка доказательств
Analysis of walletconnectchain.web.app indicates a high‑risk brand‑impersonation campaign targeting WalletConnect users. The site is hosted on Google Firebase and resolves to the IP address 199.36.158.100, which belongs to Fastly, Inc. (AS54113) in the United States. An SSL certificate issued by Google Trust Services (WR4) is present, and the page title returned by the server is "Decentralized Blockchain Protocol," a generic phrase that does not reference WalletConnect but aligns with the declared crypto‑scam intent. The domain is currently offline, returning an HTTP 404 status, and has been taken down as of the report date.
VirusTotal has recorded 12 detections out of 95 security vendors, confirming that multiple scanners identify malicious behavior. The domain is listed on five security blocklists and is actively blocked by services such as PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura. The infrastructure shows HSTS and HTTP/3 support, typical of modern Firebase deployments, but no nameserver information is disclosed. The evidence demonstrates a clear attempt to impersonate the WalletConnect brand, likely to lure victims into a crypto‑related fraud.
Uncertainty remains regarding the exact payload or phishing kit used, as no page content has been captured beyond the title and HTTP status. Defenders should immediately block the domain at perimeter firewalls, DNS resolvers, and proxy filters, and add it to internal threat intelligence feeds. Continuous monitoring of the associated IP range and Fastly CDN edge nodes is advisable, as threat actors may shift to adjacent hosts. Given the existing blocklist coverage and vendor detections, inclusion of the domain in automated URL filtering rules will mitigate exposure while further forensic collection is pursued.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
6 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Технологии
Выявлено 3 технологии с высокой уверенностью
Анализ VirusTotal
Архивные доказательства
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание