learn-en-thorchan-wallet[.]pages[.]dev
“Suspected phishing site | Cloudflare”
learn-en-thorchan-wallet.pages.dev — Контент недоступний. Тип шахрайства: Wallet/seed Phishing. Зведення доказів: VirusTotal 3/94 (ADMINUSLabs, Fortinet, LevelBlue); PhishDestroy score 65/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies learn-en-thorchan-wallet.pages.dev as an active crypto drainer campaign leveraging a fake Thorchain Wallet interface to siphon cryptocurrency assets. The threat actor employs a drainer kit designed to intercept and divert user transactions to attacker-controlled wallets, exploiting the trust associated with the Thorchain ecosystem. This domain is part of a broader campaign targeting users seeking alternative wallet solutions or unfamiliar with the legitimate Thorchain Wallet interface. This domain was flagged with a VirusTotal detection score of 3/95, indicating it remains undetected by most antivirus engines as of the latest scan. The domain is registered through Cloudflare, Inc., a common tactic to obscure the true registrant while leveraging Cloudflare’s infrastructure for hosting. It resolves to IP 172.66.47.171, a Cloudflare IP range frequently associated with malicious or phishing content. The SSL certificate is issued by Google Trust Services, which adds a veneer of legitimacy but does not guarantee the site’s safety. Notably, the domain has not been flagged by Google Safe Browsing (GSB) and remains unlisted on major blocklists, increasing its potential to deceive users. The domain is currently active and poses an immediate risk to users who interact with it, particularly those seeking to connect their wallets or manage assets. PhishDestroy has flagged this domain under investigation (Unique Seed: aac8c7) and is monitoring its activity for further indicators of compromise. Users are advised to avoid interacting with this domain and to verify any similar domains using PhishDestroy’s tools. The lack of detections and blocklist entries suggests this campaign is in its early stages, but the use of a drainer kit and fake wallet interface underscores its high-risk nature. Immediate action is required to prevent asset loss, and users should report any encounters with this domain to PhishDestroy for further analysis.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of learn-en-thorchan-wallet.pages.dev · checked Apr 3, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога