Skip to content Dark Web Informer - Cyber Threat Intelligence
IOC

IOC Alert: Suspicious C2 Domain Masquerading as Guarda Wallet – app-guarda[.]com

📖 Overview
A domain-based indicator has been identified hosting a fake cryptocurrency wallet page imitating Guarda Wallet. This domain is linked to command-and-control infrastructure and represents a high-confidence threat. Users interacting with it risk credential theft and potential loss of digital assets.


📌 Key Details

FieldInformation
TypeDomain
Indicatorapp-guarda[.]com
Threat TypeBotnet C2
Malwareunknown
Confidence100%
Date01 Sep 2025 – 14:24:17 UTC
Tagsc2
ReporterPunisherRipRip

🔎 URLScan Result
Page Title: Guarda Wallet
Screenshot: https://urlscan.io/screenshots/01990200-977c-718c-9512-7c14981e610e.png
Result: https://urlscan.io/result/01990200-977c-718c-9512-7c14981e610e/


📡 Related Intelligence
WHOIS Record: https://who.is/whois/app-guarda.com
VirusTotal Report: https://www.virustotal.com/gui/domain/app-guarda.com


🛡️ Defensive Guidance

  • Block app-guarda[.]com at DNS, proxy, and endpoint layers.
  • Monitor for user attempts to interact with fake cryptocurrency wallet infrastructure.
  • Hunt for credential exfiltration attempts in endpoint telemetry.
  • Review logs for connections to infrastructure imitating legitimate wallet services.

Latest