reformmembershipcert[.]wasmer[.]app
“Navy Federal Credit Union - Our Members are the Mission®”
reformmembershipcert.wasmer.app — İçerik kullanılamıyor. Marka kimliğine bürünme: Nfcu; Dolandırıcılık türü: Generic Phishing. Kanıt özeti: VirusTotal 25/94 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); URLQuery 3 alerts; URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 95/100. Kayıt kuruluşu: Squarespace Domains II.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
PhishDestroy identifies reformmembershipcert.wasmer.app as an active crypto drainer impersonating Wasmer App membership credentials, currently under investigation by security teams. This domain leverages brand impersonation to trick users into connecting crypto wallets or submitting sensitive login details under the guise of a legitimate Wasmer App certificate. The threat is amplified by its use of a Let's Encrypt SSL certificate, which may lull visitors into a false sense of security by displaying the familiar padlock icon in browsers. With Google Safe Browsing already flagging it under SOCIAL_ENGINEERING and zero detections on VirusTotal (25/95), the domain remains undetected by many security engines, increasing its potential to deceive users. Technical indicators further confirm the suspicious nature of this domain. It resolves to IP address 62.210.172.150, a hosting infrastructure with a history of association with malicious campaigns. While the exact creation date and registrar details are not provided in available intelligence, the combination of a clean VirusTotal score and active SOCIAL_ENGINEERING flag raises immediate concerns. The domain’s naming convention—reformmembershipcert.wasmer.app—suggests an attempt to mimic legitimate Wasmer App services, likely targeting users familiar with the platform who may unknowingly trust the certificate-like subdomain structure. Users who have visited reformmembershipcert.wasmer.app should assume potential exposure of their credentials or crypto wallet connections. Immediately disconnect any connected wallets, revoke any granted permissions, and scan devices for malware using reputable security software. Avoid interacting with any prompts or requests on the site, as they are likely designed to drain crypto assets or harvest login details. Report the domain to your browser’s safe browsing tool or platforms like Google Safe Browsing to help block future access. If you entered login credentials, change passwords for all related accounts and enable two-factor authentication where available. Monitor crypto wallets and financial accounts closely for unauthorized transactions.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | javascript.write.md5:cfd2a33c8f058099ca931f7ec48fe566 |
malware | Detects file containing Telegram Bot API |
| OpenDNS | reformmembershipcert.wasmer.app |
phishing | Phishing Block |
| DNS4EU | reformmembershipcert.wasmer.app |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Registration: wasmer.app
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For the registrable domain wasmer.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of reformmembershipcert.wasmer.app · checked Apr 3, 2026
Kanıtlar ve Dış Raporlar
PD-20260403-9E8E0E Recipient: abuse@wasmer.io Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin