defillama-wallet[.]blogspot[.]com
“DefiLlama Wallet – Manage DeFi Assets Securely”
defillama-wallet.blogspot.com — Контент недоступний. Уособлення бренду: Arbitrum; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 1/95 (ChainPatrol); PhishDestroy score 55/100. Реєстратор: MarkMonitor.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain defillama-wallet.blogspot.com is a phishing site designed to function as a crypto drainer, a type of scam that automatically siphons cryptocurrency from connected wallets. It does not impersonate a specific legitimate brand but uses the name 'DefiLlama' to appear credible. As of the latest verification, defillama-wallet.blogspot.com has been taken offline, though it previously posed an elevated risk to users who interacted with it.
Technical analysis shows that defillama-wallet.blogspot.com was flagged by 1 of 95 security vendors on VirusTotal, including ChainPatrol. It appeared on 1 security blocklist (PhishDestroy) but was not flagged by Google Safe Browsing. The domain was registered through MarkMonitor, Inc. on July 31, 2000, and resolved to the IPv6 address 2a00:1450:4001:813::2001, hosted by Google LLC in Germany. The SSL certificate was issued by Google Trust Services / WE2, and the observed page title was 'DefiLlama Wallet – Manage DeFi Assets Securely'. The site returned an HTTP 404 status at the time of assessment and was detected using technologies such as Blogger, Java, Python, OpenGSE, and HTTP/3.
Users who connected a wallet to defillama-wallet.blogspot.com should immediately revoke all token approvals using a tool like Etherscan’s token approval checker or Revoke.cash. Funds should be moved to a new, secure wallet to prevent further unauthorized transactions. Victims are advised to report the domain to their wallet provider, local cybercrime authorities, and platforms like ChainPatrol or PhishTank to aid in takedown efforts. Enabling two-factor authentication on all accounts and monitoring for suspicious transactions is also recommended.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 5 identified
Blogger is a blog-publishing service that allows multi-user blogs with time-stamped entries.
www.blogger.com 100% впевненостіJava is a class-based, object-oriented programming language that is designed to have as few implementation dependencies as possible.
java.com 100% впевненостіOpenGSE is a test suite used for testing servlet compliance. It is deployed by using WAR files that are deployed on the server engine.
code.google.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога