lichen-network-wallet[.]pages[.]dev
“LichenWallet - Your Gateway to Lichen”
lichen-network-wallet.pages.dev — Bilinen son aktif (HTTP 200). Dolandırıcılık türü: Crypto Scam. Kanıt özeti: VirusTotal 4/94 (ADMINUSLabs, alphaMountain.ai, Fortinet, Phishing Database); PhishDestroy score 77/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Analysis of the domain lichen-network-wallet.pages.dev indicates it is actively hosting a crypto-draining operation targeting users of a service branded as LichenWallet. The domain, registered on March 23, 2026, through Cloudflare, Inc., resolves to the IP address 172.66.44.204 and is currently flagged by at least one security blocklist. The page title, 'LichenWallet - Your Gateway to Lichen,' suggests an attempt to impersonate a legitimate cryptocurrency wallet or platform, though no confirmed legitimate counterpart has been identified in available intelligence. The domain is hosted on Cloudflare infrastructure, utilizing technologies such as HSTS, cdnjs, and HTTP/3, which are commonly employed to enhance security and performance but may also obscure malicious activity from casual inspection. Security vendors have detected this domain with varying levels of confidence: four of 95 engines on VirusTotal classify it as malicious. While this detection rate is not overwhelming, it aligns with known patterns of crypto-draining infrastructure, which often evades broad detection due to rapid deployment and short-lived operations. The use of a Let's Encrypt SSL certificate further complicates automated detection, as it provides a veneer of legitimacy. Defenders should note that the domain remains active as of July 12, 2026, and has not been widely blocked, increasing the likelihood of exposure to end users. Given the high-risk classification and the specific threat type (crypto drainer), organizations should prioritize blocking this domain at the network level. Monitoring for connections to 172.66.44.204 and related subdomains under *.pages.dev may help identify compromised endpoints. Additional analysis of the site's content and backend infrastructure is recommended to determine the exact mechanisms of the drainer and any associated wallet addresses. Until further intelligence is gathered, treating this domain as malicious and preventing user interaction is advised.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Adli İstihbarat
Teknolojiler · 4 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of lichen-network-wallet.pages.dev · checked Mar 22, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin