kwallet.trade
“K-Wallet - BSC & Tron Crypto Wallet”
www.kwallet.trade is an active crypto drainer phishing domain impersonating a BSC & Tron wallet. Resolves to 82.112.226.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Сводка доказательств
This domain, www.kwallet.trade, is flagged as an active crypto drainer phishing site designed to target users of Binance Smart Chain (BSC) and Tron cryptocurrency wallets. The site masquerades as a legitimate wallet service under the name 'K-Wallet,' luring victims into connecting their wallets to malicious smart contracts that siphon funds without authorization. Analysis indicates the use of a drainer kit, likely deployed to automate the theft of digital assets upon wallet connection, a common tactic in recent cryptocurrency phishing campaigns. Infrastructure analysis reveals the following technical indicators: the domain resolves to IP address 82.112.226.231 and was registered on September 11, 2025, through GoDaddy.com, LLC. The SSL certificate is issued by Let's Encrypt, a detail often exploited by threat actors to lend a false sense of legitimacy. As of the latest scan, VirusTotal reports 2 out of 95 security vendors flagging the domain, while it appears on two independent security blocklists, including PhishDestroy and OISD. The domain's recent creation date and immediate malicious activity suggest a short-lived, high-impact campaign typical of crypto drainer operations. The site remains active and poses an elevated risk to users who may unknowingly connect their wallets. Immediate response actions include blocking the domain at the DNS level, revoking wallet access to any connected smart contracts, and monitoring for unauthorized transactions. Despite its presence on blocklists, the domain may still evade detection in some environments due to its recent registration and low initial detection rate. Users are advised to verify wallet addresses, avoid interacting with unsolicited wallet prompts, and cross-reference domain details with official sources before engaging with any cryptocurrency service.
Forensic History & Detection Timeline
-
VirusTotal Detections Update Jun 26, 2026 · 03:58 UTCVirusTotal scanner detections updated from 0 to 2. Added scanner alerts: Gridinsoft, SOCRadar.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ методов обнаружения и уклонения
Проверка маскировки и распределения трафика
Не наблюдается
В сохраненном скане не было обнаружено никаких следов маскировки
Сохраненные данные сравнения данных сканера и браузера для данного хоста, а также проверка отпечатков в режиме реального времени для систем распределения трафика типа «Кейтаро».
- Сохраненный флаг маскировки
- Не наблюдается
- Оценка маскировки
- 0/6
- Последнее сканирование на наличие маскировки
Примечание к сканированию: alive_content: raw=ok; http=200; via=https_proxy
Сохранённый снимок · 3 sources
Аналитика доменов
Технические деталиDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 2 identified
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of kwallet.trade · checked Jun 26, 2026
Сообщения сообщества
Сообщил 1 участник сообщества; впервые замечено 30.05.2026
- Сохранённые сообщения
- 1
- Уникальные URL
- 1
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание