woalletcaonanecct[.]gitbook[.]io
“WalletConnect - Bridge to Multi-Chain Wallets | us”
woalletcaonanecct.gitbook.io — Неперевірений. Уособлення бренду: Across; Тип шахрайства: Wallet/seed Phishing. Зведення доказів: VirusTotal 14/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); CF Radar malicious; PhishDestroy score 92/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain woalletcaonanecct.gitbook.io is currently active and is being used to impersonate the WalletConnect brand in a wallet/seed phishing campaign. The site is hosted behind Cloudflare, Inc., with authoritative nameservers dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com, and resolves to the IP address 104.18.40.47, which is located in the United States and belongs to ASN 13335 (Cloudflare). The web server presents a valid SSL certificate issued by Google Trust Services (WE1) and negotiates HTTP/3, returning an HTTP 307 redirect response. The page title returned by the server is "WalletConnect - Bridge to Multi-Chain Wallets | us," suggesting a deliberate attempt to mimic the legitimate WalletConnect service.
VirusTotal analysis shows that 16 of 95 security vendors have flagged the domain as malicious, and the domain appears on one public security blocklist. It is also listed as blocked by PhishDestroy. Independent reputation scoring (Gridinsoft) assigns a trust score of 0 out of 100, reinforcing the malicious assessment. The domain was originally registered on March 30, 2014, indicating that the infrastructure has been retained for an extended period despite the recent activity.
While the observed metadata confirms the presence of brand‑impersonating infrastructure, the exact content served to victims has not been publicly disclosed, leaving the specific phishing workflow uncertain. Defenders should treat any traffic to woalletcaonanecct.gitbook.io as hostile: block the domain at perimeter firewalls and DNS resolvers, add the IP address 104.18.40.47 to deny lists, and enforce URL filtering that matches the observed page title. Continuous monitoring of Cloudflare‑hosted assets for similar patterns is advised, as the provider may host both legitimate and malicious sites.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога