Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is domainabuse@tucows.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
w3connectnetwork[.]com
“Home - W3connectnetwork - A crypto buy and sell marketplace”
w3connectnetwork.com — Останній відомий активний (HTTP 200). Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 1 alert; 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 100/100. Реєстратор: TUCOWS.COM, CO.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
w3connectnetwork.com has been confirmed as an active credential theft domain impersonating legitimate web3 connectivity services. The infrastructure is designed to harvest login credentials and session tokens, likely targeting users of decentralized applications. The domain mimics professional branding to deceive victims into entering sensitive wallet or exchange credentials, which are then exfiltrated to attacker-controlled endpoints. No specific drainer kit has been publicly identified, but the site's behavior aligns with known credential harvesting campaigns often paired with crypto-theft malware.
Technical indicators for w3connectnetwork.com are as follows: VirusTotal detection ratio stands at 4 out of 95 security vendors, with a fluctuating but persistent threat status. The domain was registered through TUCOWS.COM, CO., resolving to IP address 162.250.126.107. While the exact creation date is not provided in open intelligence, this IP has been associated with multiple malicious domains in recent campaigns. Google Safe Browsing (GSB) has flagged the domain, and it currently appears on 3 blocklists, indicating widespread recognition as a threat.
The domain remains active and continues to operate without interruption. Immediate organizational action includes blocking access at the DNS and network levels, inspecting DNS query logs for lateral movement, and ensuring endpoint detection rules are updated to quarantine any related artifacts. Despite these measures, residual risk persists due to the domain's recent activity and the potential for evasion tactics such as fast-flux DNS or rapid domain rotation. Continuous monitoring is required to prevent credential compromise and downstream crypto theft.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | w3connectnetwork.com |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 3 identified
High-performance web server compatible with Apache configurations.
Lightweight JavaScript framework for composing behavior directly in markup.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of w3connectnetwork.com · checked Mar 26, 2026
Аналіз конфігурації сайту
Докази та зовнішні звіти
PD-20260325-1D4024 Recipient: domainabuse@tucows.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога