web3-walletdapp-remote-protocol[.]pages[.]dev
“Suspected phishing site | Cloudflare”
证据摘要
The domain web3-walletdapp-remote-protocol.pages.dev was registered on February 21, 2026 through Cloudflare, Inc. and resolves to the IP address 172.66.44.118, which belongs to Cloudflare’s AS13335 network located in the United States. No SSL certificate is presented for the host, and the HTTP response currently returns a generic Cloudflare page titled "Suspected phishing site | Cloudflare." The site has been taken offline and is listed as blocked by the PhishDestroy blocklist, indicating that defenders have already taken action to prevent client access. VirusTotal analysis shows that seven of ninety‑three security vendors flagged the domain, reinforcing the suspicion that it is being used for malicious activity.
The threat classification supplied identifies the site as a "Crypto Scam" with a specific focus on draining cryptocurrency assets, aligning it with the broader category of crypto drainer operations. Concrete evidence therefore includes the registrar information, IP ownership, lack of TLS, blocklist entry, and the vendor detection count. What remains uncertain is the exact payload or phishing flow that was delivered before the takedown, as no page content beyond the Cloudflare warning has been captured.
defenders should continue to monitor the IP address for any re‑hosting attempts, enforce DNS‑level blocking for the domain, and update intrusion‑prevention signatures to capture traffic matching the observed host header. Because the domain is already offline, immediate remediation focuses on preventing resurgence and ensuring that any compromised credentials or wallet addresses reported by victims are revoked or moved to secure storage. Continuous threat‑intel feeds should be consulted for any related indicators of compromise that might appear in future campaigns targeting similar web3 wallet interfaces.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月10日
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控