wlfiprime[.]com
“WLFI Wallet - Secure Your Cryptocurrencies with WLFI.co”
Збережене спостереження
Зафіксована відмінність заголовків
Зведення доказів
wlfiprime.com is currently active and has been classified as a high‑risk crypto‑scam that impersonates the Arbitrum brand. The site presents the page title “WLFI Wallet – Secure Your Cryptocurrencies with WLFI.co”, which aligns with the reported phishing kit “Seed Phrase Phishing”. The domain was registered on 17 December 2025 through Gname.com Pte. Ltd. and resolves to the Cloudflare‑hosted address 188.114.97.3, located in the United States under ASN 13335 (Cloudflare, Inc.). DNS resolution uses the Cloudflare authoritative nameservers coco.ns.cloudflare.com and matteo.ns.cloudflare.com. The TLS certificate is issued by Google Trust Services under the WE1 root, indicating a valid HTTPS endpoint despite the malicious intent.
Technical inspection shows an HTTP 301 redirect response, and the front‑end stack is built on Vue.js with Cloudflare Browser Insights and HTTP/3 enabled. The domain appears on a single security blocklist and has been flagged by PhishDestroy. Reputation scoring from Gridinsoft assigns a trust score of 0 out of 100, confirming the malicious nature. VirusTotal analysis reports that 8 of 95 scanning engines have identified the domain as malicious, reinforcing the threat assessment. Evidence confirms that the site is designed to harvest seed phrases from users who believe they are interacting with an official Arbitrum wallet service.
No additional content has been publicly disclosed, and the exact phishing page layout remains unverified. Defenders should block the domain at network perimeter, add the IP address 188.114.97.3 to deny lists, and monitor for any DNS queries to the associated Cloudflare nameservers. Users of Arbitrum‑related services should be warned about the impersonation attempt and instructed to verify URLs before entering wallet credentials. Continuous monitoring of the domain’s certificate and DNS changes is recommended, as the infrastructure could be repointed to new IPs under the same Cloudflare account.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
VirusTotal
8 → 9
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of wlfiprime.com · checked Mar 2, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога