connecter[.]o9bbuahbuwgfg73g8a8gf83gf8u3gfgj[.]workers[.]dev
“Wallet Adapter”
connecter.o9bbuahbuwgfg73g8a8gf83gf8u3gfgj.workers.dev — Doğrulanmamış. Dolandırıcılık türü: Crypto Scam. Kanıt özeti: VirusTotal 8/91 (ADMINUSLabs, Chong Lua Dao, CRDF, CyRadar, Forcepoint ThreatSeeker); PhishDestroy score 83/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain is flagged as a high-risk fake crypto wallet drainer targeting cryptocurrency users through deceptive wallet adapter interfaces. The threat operates by mimicking legitimate wallet connection prompts to trick victims into authorizing malicious transactions, resulting in unauthorized fund transfers from connected wallets. Analysis indicates this is a targeted financial attack vector rather than a generic credential harvester. Infrastructure analysis reveals the domain was registered through Cloudflare on February 21, 2026, resolving to IP 172.67.168.239 (US, AS13335 Cloudflare). VirusTotal detection shows 8/95 security vendors flagging the domain, while PhishDestroy maintains an active block. The domain appears on one security blocklist and presents a valid SSL certificate issued by Google Trust Services (WE1). The page title 'Wallet Adapter' directly correlates with known crypto wallet drainer patterns observed in recent campaigns. Organizations should implement immediate mitigation measures including: (1) blocking the domain and IP at firewall/DNS level, (2) adding detection rules for 'Wallet Adapter' page titles in web filtering systems, (3) deploying endpoint protection with crypto wallet-specific behavioral monitoring, (4) implementing transaction signing requirements for all wallet interactions, and (5) conducting user awareness training focused on verifying wallet connection prompts. Network defenders should monitor for connections to 172.67.168.239 and similar Cloudflare Workers subdomains with random character patterns. Given the financial nature of this threat, affected users should immediately revoke all wallet authorizations and transfer assets to new wallets.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 4 identified
Fast CDN for everything on npm — serves raw files from npm packages.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin