defillama-protocol-eng[.]pages[.]dev
“DeFiLlama Wallet – Track and Manage DeFi Assets Securely”
Збережене спостереження
Зафіксована відмінність заголовків
Зведення доказів
Analysis of the domain defillama-protocol-eng.pages.dev indicates it was actively impersonating the Across protocol, a known decentralized finance (DeFi) platform, as part of a wallet and seed-phishing campaign. The domain was registered on March 10, 2026, through Cloudflare, Inc., and resolved to the IP address 188.114.96.3, hosted on Cloudflare's infrastructure (AS13335). At the time of assessment, the domain returned an HTTP 403 status, suggesting access was restricted or the page had been taken offline. The SSL certificate, issued by Google Trust Services (WE1), and the use of Cloudflare nameservers (brodie.ns.cloudflare.com and georgia.ns.cloudflare.com) align with typical phishing infrastructure leveraging content delivery networks to obscure origin servers. Detection data from July 25, 2026, shows the domain was flagged by 6 of 94 security vendors on VirusTotal and appeared on three security blocklists, including PhishDestroy, MetaMask, and SEAL.
The page title, 'DeFiLlama Wallet – Track and Manage DeFi Assets Securely,' directly references DeFiLlama, a legitimate analytics platform, while the scam type explicitly targets wallet and seed-phishing, a tactic commonly used to compromise cryptocurrency holdings. Gridinsoft assigned the domain a trust score of 0/100, further corroborating its malicious classification. Infrastructure analysis reveals the use of HTTP/3 and HSTS, technologies often employed to enhance perceived legitimacy and evade basic detection mechanisms. The domain's registration details and hosting provider are consistent with patterns observed in other phishing campaigns, where threat actors exploit Cloudflare's services to mask their operations.
While the exact content of the phishing page remains unanalyzed, the available evidence—including the page title, brand impersonation, and detection by multiple security vendors—confirms its intent to deceive users into disclosing sensitive wallet credentials.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
8 зовнішніх джерел під наглядом Збігів немає
Хронологія виявлення
-
VirusTotal
0 → 4
Технології
Виявлено 3 технології з високою впевненістю
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of defillama-protocol-eng.pages.dev · checked Mar 10, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога