wefi-global[.]com
Kiểm tra lừa đảo và bảo mật cho wefi-global.com
“Home - WeFi Cryptobank”
wefi-global.com — Hoạt động được biết đến lần cuối (HTTP 303). Loại lừa đảo: Crypto Drainer. Tóm tắt bằng chứng: VT 2/91 (CRDF, Gridinsoft); URLQuery 3 alerts; URLScan no malicious verdict; GSB no flag; BL 2 (MetaMask, SEAL); PD 81/100. Nhà đăng ký: Key-Systems.
Phân tích chi tiết của PhishDestroy AI bên dưới được giữ bằng tiếng Anh để bảo toàn hồ sơ pháp chứng gốc.
This domain, wefi-global.com, operates as a crypto drainer scheme designed to impersonate the legitimate WeFi Cryptobank platform. Analysis of the site reveals infrastructure tailored for credential theft and unauthorized cryptocurrency transactions, with the page title explicitly displaying 'Home - WeFi Cryptobank.' The fraudulent site employs a deceptive interface to trick users into connecting their digital wallets, enabling attackers to siphon funds directly from compromised accounts. The presence of wallet-specific blocklists, including MetaMask and SEAL, further confirms the domain’s role in targeting cryptocurrency holders with malicious intent.
Infrastructure analysis reveals multiple indicators of compromise. The domain was registered on February 21, 2026, through Key-Systems GmbH, an unusual creation date suggesting potential backdating or misuse of registrar services. It resolves to the IP address 178.63.44.224 and is currently flagged by 3 security blocklists. Detection engines on VirusTotal report 2 out of 95 vendors identifying the domain as malicious, while additional technologies such as WordPress, Plesk, and Let’s Encrypt SSL certificates are employed to mimic legitimate financial platforms. The Gridinsoft trust score of 0/100 underscores the domain’s high-risk classification.
Users who have interacted with wefi-global.com should immediately disconnect any linked wallets and revoke permissions for connected decentralized applications. It is critical to transfer remaining funds to a new, secure wallet address and monitor transaction histories for unauthorized activity. If credentials were entered, affected parties should assume compromise and initiate password resets for all associated accounts. Security teams are advised to update blocklists with the domain and IP address 178.63.44.224 to prevent further exposure. No further engagement with the domain should occur, as it remains a verified threat to digital asset security.
Tình báo an ninh mạng
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | www.youtube.com/s/player/4e51e895/player_es6.vflset/en_us/base.js |
audit | Hunting_JS_WebAssembly |
| Nextron YARA rules | wefi-global.com/wp-content/uploads/2025/12/2.gif |
malware | Detects files with GIF headers and format anomalies - which means that this image could be an obfuscated file of a different type |
| Nextron YARA rules | wefi-global.com/wp-content/uploads/2025/12/1.gif |
malware | Detects files with GIF headers and format anomalies - which means that this image could be an obfuscated file of a different type |
Pipeline ứng phó với các mối đe dọa
Trạng thái trong danh sách chặn công khai
Bản chụp đã lưu
Thông tin về tên miền
Chi tiết kỹ thuậtDNS, SAN trong SSL, dấu thời gian
ICANN OVERSIGHT
Bối cảnh công nhận và RAA
Bối cảnh công nhận và RAA
ICANN Đã Nhận Tiền. Trách Nhiệm Giải Trình Thì Không Thấy Đâu.
Đối với gTLD này, nhà đăng ký tên miền nêu trên hoạt động theo hợp đồng với ICANN. ICANN thu các khoản phí hằng năm, phí biến đổi và phí theo giao dịch gắn với việc đăng ký, gia hạn và chuyển nhượng.
Công nhận: đã kiếm ra tiền. Trách nhiệm giải trình: vui lòng kiểm tra lại sau.
Rồi phép màu bắt đầu: ICANN viết RAA §3.18, nhà đăng ký tự điều tra hành vi lạm dụng ngay trong chính nhóm khách hàng của mình, còn nạn nhân cung cấp bằng chứng miễn phí trong khi mọi tầng nấc đều chờ người khác hành động. Nếu điều đó khiến nạn nhân cảm thấy an toàn hơn thì tuyệt vời—hóa đơn đã phát huy tác dụng.
Công nghệ · 12 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
Popular CSS framework for responsive, mobile-first web development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Plugin to detect and restore deprecated jQuery features.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Phân tích của VirusTotal
Bằng chứng lưu trữ
Bằng chứng và các báo cáo bên ngoài
Bạn có bị ảnh hưởng bởi trang web này không?
Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.
Hãy báo cáo với chính quyền địa phương
Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.
Giới thiệu về báo cáo này: wefi-global.com
Báo cáo này trình bày bằng chứng được lưu trữ mới nhất có sẵn cho PhishDestroy. Dấu thời gian nguồn được hiển thị nếu có; tính khả dụng và phán quyết của nhà cung cấp có thể thay đổi sau khi thu thập.
Trang web được chụp hiển thị tiêu đề trang “Home - WeFi Cryptobank”.
Kể từ 07/08/2026, wefi-global.com đã được phát hiện từ các công cụ bảo mật 2.
Nếu bạn cho rằng danh sách này không chính xác, nộp đơn kháng cáo. Để tìm hiểu về phương pháp của chúng tôi, hãy truy cập Trang câu hỏi thường gặp.
Kiểm tra bất kỳ tên miền nào
Phân tích mối đe dọa bằng cách sử dụng danh sách chặn được lưu trữ, WHOIS, DNS và bằng chứng quét công khai
Quét ngayBáo cáo lừa đảo qua email
Hãy gửi các tên miền đáng ngờ đến cơ sở dữ liệu mối đe dọa của chúng tôi — để bảo vệ cộng đồng
Báo cáoDòng tin tức về các mối đe dọa thời gian thực
Các báo cáo lừa đảo gần đây và những thay đổi về tính khả dụng được quan sát thấy
Theo dõiLuôn cập nhật thông tin, luôn an toàn
Theo dõi các mối đe dọa đang diễn ra hoặc phản đối danh sách này nếu bạn cho rằng đây là kết quả báo động sai