MALICIOUS — CRITICAL
waecux[.]com
PhishDestroy identifies waecux.com as a domain currently under investigation for suspected cryptocurrency drainer activity.
- VirusTotal
- 2/91
- Blocklists
- 2 · MetaMask, SEAL
- Доступність
- Останній відомий активний · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
It contains 2 outgoing records; the latest is dated . The recorded recipient is abuse@trustname.com.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
waecux.com — Останній відомий активний (HTTP 200). Уособлення бренду: Cryptoscam; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 2/91 (Gridinsoft, Netcraft); URLScan malicious verdict; Spamhaus DBL_SPAM; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 86/100. Реєстратор: Fewmoretaps OU d/b/a T….
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
PhishDestroy identifies waecux.com as a domain currently under investigation for suspected cryptocurrency drainer activity. The site is active and has not yet been flagged by major security vendors, which increases the risk of successful exploitation for unauthorized fund transfers. Organizations and users should treat this domain with extreme caution and avoid any interaction until further analysis is completed.
This domain was flagged with 0 detections out of 95 VirusTotal vendors as of the latest scan, indicating it remains under the radar of most detection engines. The domain was registered through Fewmoretaps OU d/b/a Trustname.com, resolves to IP 188.114.97.3, and was created on April 29, 2026. Additionally, it utilizes a Let's Encrypt SSL certificate, which may be leveraged to appear legitimate. The combination of zero detections, recent registration, and lack of historical blocklist presence suggests this domain is likely in its initial deployment phase, increasing the risk of successful phishing or drainer operations.
Given the active status and early-stage evasion tactics, immediate defensive actions are warranted. Security teams should implement network-level blocks for the domain and associated IP address (188.114.97.3) to prevent outbound connections. Additionally, end-users should be alerted to avoid visiting waecux.com and to report any suspicious transactions involving cryptocurrency wallets. Further investigation into the domain's infrastructure, including WHOIS history and SSL certificate details, is recommended to identify any additional malicious artifacts. Organizations are advised to monitor for any associations with known cryptocurrency drainer toolkits or wallet interactions that may indicate compromise.
Обсяг даних14 recorded checks
Сигнали безпеки
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Історія скарг на зловживання · 2 stored reports over 5 days · click to expand
-
Report #2 ICANN CC 119h still active May 9, 2026 · 00:50 UTCESCALATION #2 (119h active): Phishing - waecux[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
-
Report #3 ICANN CC 215h still active May 13, 2026 · 00:59 UTCESCALATION #3 (215h active): Phishing - waecux[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
Технології · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of waecux.com · checked May 3, 2026
Докази та зовнішні звітиIndependent lookups and source reports
PD-20260503-572821 Recipient: abuse@trustname.com Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.