ai-defichain[.]pages[.]dev
“Encrypted-Server - We are unifying Web3 by providing best-in-class, self-custodial, and multichain …”
已存储的观测记录
观测到的标题差异
证据摘要
This domain, ai-defichain.pages.dev, is currently under investigation for operating as an active crypto drainer phishing endpoint. Analysis indicates the site specifically targets cryptocurrency users by simulating a legitimate Web3 platform interface, employing social engineering tactics to induce victims into connecting wallets and authorizing malicious transactions. The threat type—crypto drainer—is particularly severe due to its direct financial impact, enabling unauthorized transfer of digital assets from compromised wallets to attacker-controlled addresses without user consent. Infrastructure analysis reveals the domain is hosted on Cloudflare’s content delivery network, registered through Cloudflare, Inc., and resolves to the IP address 172.66.44.103, geolocated within the United States under AS13335. Despite its active status, the domain has not yet been widely flagged, with only 0 out of 95 security engines on VirusTotal detecting malicious activity at the time of assessment. A single security blocklist, PhishDestroy, has identified and blocked the domain. The SSL certificate is issued by Google Trust Services (WE1), providing a superficial layer of legitimacy that may reduce user suspicion. The page title, 'Encrypted-Server - We are unifying Web3 by providing best-in-class, self-custodial, and multichain support,' closely mimics the branding and messaging of established decentralized finance platforms, increasing the likelihood of successful deception. To mitigate the risks posed by this crypto drainer, users are advised to exercise extreme caution when interacting with unsolicited links, particularly those promoting Web3 services or airdrops. Wallet connections should only be authorized on verified, official platforms, and users should scrutinize domain names for subtle misspellings or unusual subdomains. Enabling transaction simulation tools and revoking unnecessary smart contract approvals via blockchain explorers can prevent unauthorized asset transfers. Network-level protections, such as DNS filtering or endpoint security policies, should be configured to block known malicious domains, including this one. Given the domain’s low detection rate, manual verification of platform authenticity through official communication channels is strongly recommended before engaging with any Web3-related service.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
技术
识别出 5 项高置信度技术
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控