thegraph-frontend-3f1[.]pages[.]dev
“Blockchain Deploy | All in one API Deployment Tool for web3 developers”
证据摘要
PhishDestroy identifies thegraph-frontend-3f1.pages.dev as an active drainer phishing domain posing under investigation generic phishing risk. This domain attempts to impersonate The Graph project’s official frontend interface, aiming to trick users into entering private wallet keys or seed phrases into a fraudulent web form. No known drainer kit fingerprint has been extracted yet, but the landing page mimics legitimate The Graph styling and workflows to enhance credibility. The domain leverages modern hosting and SSL infrastructure to appear legitimate at first glance, which increases the risk of successful user deception. This domain resolves to IP address 188.114.97.3 and is served through Cloudflare Pages, registered via Cloudflare, Inc. with a Google Trust Services SSL certificate. As of the latest scan, VirusTotal reports 0 detections out of 95 engines, indicating it remains undetected by most antivirus and threat intelligence platforms. The domain appears to be recently created, though the exact registration date is not publicly disclosed. Google Safe Browsing (GSB) has not yet flagged the site, and no blocklist entries were found in major threat feeds. These technical indicators suggest a newly deployed infrastructure optimized to evade early detection. At present, the domain remains active and unblocked across most security platforms, posing a moderate-to-high risk to unwary users. PhishDestroy recommends immediate network-level and endpoint blocking via DNS sinkholing or firewall rules targeting 188.114.97.3 and the domain itself. Users should avoid accessing this domain and verify any The Graph-related links via official project channels. The ongoing investigation continues to assess the full scope of this campaign, including potential ties to broader credential harvesting or fund draining operations. Remaining risk is elevated due to low detection rates and the use of reputable hosting and SSL providers to lend false legitimacy.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of thegraph-frontend-3f1.pages.dev · checked Mar 31, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控