walrus[.]city
“Walrus Claiming Portal”
walrus.city — 内容不可用 (HTTP 502). 品牌冒充:Sui; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 8/93 (ChainPatrol, alphaMountain.ai, CRDF, CyRadar, Fortinet); URLQuery 1 alert; Spamhaus DBL_PHISH; PhishDestroy score 74/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies walrus.city as an elevated risk domain engaged in brand impersonation, specifically targeting the Sui blockchain project. This domain poses a concrete threat by masquerading as an official Walrus claiming portal, likely designed to harvest users' wallet credentials or private keys through a fake airdrop or token claim interface. The domain's sole purpose appears to be deceiving Sui community members into believing they are interacting with a legitimate protocol.
Technical analysis reveals multiple red flags: VirusTotal reports that 8 out of 95 security vendors flag this domain as malicious. The domain was registered on February 21, 2026, and resolves to IP address 76.76.21.98. It uses an R13 SSL certificate and appears on one security blocklist. The page title is explicitly "Walrus Claiming Portal," which directly mimics the branding of Walrus, a storage protocol built on Sui. Despite being taken offline, the domain's infrastructure and historical data remain concerning.
Users who may have interacted with walrus.city should immediately revoke any permissions granted to the site and change passwords for associated accounts. Since this is a brand impersonation attack, the safest course is to only use official channels—such as the verified Sui Foundation website or official Walrus documentation—for any token claims or protocol interactions. Enabling two-factor authentication and monitoring wallet activity for unauthorized transactions are also critical steps. PhishDestroy recommends reporting any similar domains to the Sui team and avoiding clicking on unsolicited links promoting claims or airdrops.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | walrus.city |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。