walletyeet[.]patch-demon115[.]workers[.]dev
“1sign · One signature wallet migration”
证据摘要
This domain, walletyeet.patch-demon115.workers.dev, is actively engaged in crypto drainer phishing operations targeting cryptocurrency wallet users. The site presents itself as a "One signature wallet migration" service under the page title "1sign · One signature wallet migration," likely impersonating legitimate wallet migration or authentication platforms. Analysis indicates the domain is designed to trick users into authorizing malicious transactions that drain funds from connected wallets, a tactic commonly associated with high-risk crypto drainer schemes. Infrastructure analysis reveals the domain was registered through Cloudflare, Inc., with an SSL certificate issued by Let’s Encrypt (serial number E7). It resolves to the IP address 188.114.96.3 and was created on June 15, 2026, though its recent activity suggests it may be part of an ongoing campaign. Detection metrics show the domain is flagged by 2 of 95 security vendors on VirusTotal, while it appears on two independent security blocklists. Additional tracking confirms it is currently blocked by PhishDestroy and ScamSniffer, further validating its malicious classification. The low vendor detection rate may indicate evasion techniques or the use of newly deployed infrastructure. The domain remains active as of this report, posing a significant risk to users who may interact with it. Organizations and individuals are advised to implement immediate network-level blocking of the domain and its associated IP address. Endpoint protection systems should be updated to detect and prevent access to walletyeet.patch-demon115.workers.dev. Users who may have interacted with the site should revoke any connected wallet authorizations, review transaction histories for unauthorized activity, and consider migrating funds to a new wallet if compromise is suspected. Continuous monitoring of related infrastructure is recommended, as threat actors frequently rotate domains and IPs in crypto drainer campaigns.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
检测时间线
-
VirusTotal
None → 0
技术
识别出 9 项高置信度技术
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控