connectwallet.network
“connectwallet.network”
connectwallet.network — Контент недоступний. Уособлення бренду: Unknown; Тип шахрайства: Crypto Drainer. Зведення доказів: VirusTotal 6/91 (ChainPatrol, alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft); URLQuery 3 det.; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 90/100. Реєстратор: Sav.com.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Зведення доказів
This domain, connectwallet.network, is flagged as an active crypto drainer designed to steal cryptocurrency assets from unsuspecting users. Crypto drainers operate by tricking victims into connecting their digital wallets to malicious smart contracts or fake interfaces, which then automatically siphon funds without authorization. The site may impersonate legitimate wallet services or decentralized applications (dApps) to appear trustworthy, but its sole purpose is to drain wallet balances once access is granted. Analysis indicates this domain was registered on July 14, 2025, through Sav.com, LLC, a registrar frequently used for newly created malicious infrastructure. As of the latest scan, the domain has zero detections out of 95 security engines on VirusTotal, suggesting it has not yet been widely flagged by automated systems. The site resolves to the IP address 103.224.182.246 and uses a Let's Encrypt SSL certificate, which provides encryption but does not validate legitimacy. The domain was also identified in one threat intelligence pulse on AlienVault OTX, further confirming its association with malicious activity. If you have visited connectwallet.network or connected a wallet to it, immediate action is required to mitigate potential losses. First, disconnect the wallet from all dApps and revoke any suspicious smart contract approvals using a blockchain explorer or a dedicated revoke tool. Next, transfer all remaining assets to a new, secure wallet with a fresh seed phrase. Monitor the original wallet for unauthorized transactions and report the domain to security platforms like PhishTank or ScamAdviser to help prevent further victimization. Users should also scan their devices for malware, as some crypto drainers deploy additional payloads to maintain persistence or steal credentials.
Forensic History & Detection Timeline
-
Domain Status Transition Sep 11, 2026 · 00:03 UTCDomain state transitioned from alive to dead.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- Оцінка маскування
- 0/6
- Last cloaking scan
Scanner note: dns_error: raw=dns_error; via=local_dns_prefilter
Збережений знімок · 2 sources
Аналітика доменів
Технічні подробиціDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
PD-20260702-92B483 Recipient: abuse-trusted.savcom@in.wixanswers.com Abuse notice text as sent to the provider
Policy Violations: Illegal Activities: Active phishing operation targeting victims Fraud & Deception: Impersonation of legitimate services Identity Theft: Collection of credentials under false pretenses Applicable Laws (Unknown): International Anti-Cybercrime Regulations Budapest Convention on Cybercrime Universal Fraud Prevention Laws Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws. Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога