imtoken-wallet[.]org[.]cn
“imToken Download - imToken Wallet | Leading Digital Asset Wallet”
ملخص الأدلة
Analysis of imtoken-wallet.org.cn indicates an active brand‑impersonation campaign targeting Discord users. The domain was registered on February 21, 2026 through Dominet (HK) Limited and resolves to IP address 38.6.207.3, which is hosted in the United States under ASN 398823 (PEG TECH INC). Network fingerprints show the web server runs Nginx with HTTP/3 enabled and enforces HSTS, while the TLS certificate is issued by Let’s Encrypt (R12). An HTTP request returns status 200 and the page title reads "imToken Download - imToken Wallet | Leading Digital Asset Wallet", suggesting the site is masquerading as a cryptocurrency wallet downloader.
The campaign is classified as Wallet/Seed Phishing and explicitly lists Discord as the impersonated brand. VirusTotal scans report five of ninety‑three security vendors flagging the domain, and PhishDestroy has already blocked it; the domain appears on one additional security blocklist. Reputation services give the domain a Gridinsoft trust score of zero out of one hundred, reinforcing its malicious nature.
Nameservers ns7.alidns.com and ns8.alidns.com are in use, consistent with typical fast‑flux techniques. Defenders should add imtoken-wallet.org.cn to web‑filter and DNS blocklists, monitor outbound traffic for connections to 38.6.207.3, and enforce strict URL filtering for any attempts to download cryptocurrency wallet software. Continuous re‑evaluation of the domain’s status is advised, given its recent registration date and active infrastructure.
لقطة الأدلة المرسلة
- أُرسل
- سجلات الدفتر
- 1
- معرّف القضية
PD-20260203-82053E- عنوان الصفحة الملتقطة
- imToken Download - imToken Wallet | Leading Digital Asset Wallet
- ملف PDF
- دليل PDF
الأساس القانوني
النص الكامل للدليل
Section 3.1 of AUP: The domain imtoken-wallet.org.cn is engaged in phishing activities, misleading users into providing sensitive information under false pretenses.
Section 4.2 of TOS: The registrar reserves the right to suspend services for any illegal activities, which includes the operation of fraudulent websites.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): Prohibits unauthorized access to computers and the use of fraud to obtain information.
Wire Fraud Statute (18 U.S.C. § 1343): Criminalizes schemes to defraud individuals or entities via electronic communications.
CAN-SPAM Act (15 U.S.C. § 7701): Regulates commercial email and prohibits deceptive practices in electronic communications.
Regulatory Note: Failure to act on this report may expose your organization to liability under applicable laws and could result in regulatory scrutiny. Immediate action is recommended to mitigate potential legal repercussions.
Data Coverage
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | imtoken-wallet.org.cn |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
المخطط الزمني للاكتشاف
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب