phantomwnallet[.]webflow[.]io
“Phantom Wallet - Connect Your Wallet - Phantom”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
The domain phantomwnallet.webflow.io was observed delivering a crypto‑scam impersonating the Phantom wallet service. Registration records show the domain was created on 08 May 2013 and is listed under the MarkMonitor, Inc. registrar, a provider commonly associated with legitimate brand‑protection services. The authoritative name servers resolve to journey.ns.cloudflare.com and lamar.ns.cloudflare.com, indicating Cloudflare’s DNS infrastructure. DNS resolution points to the IPv4 address 104.18.36.248, which belongs to AS13335 Cloudflare, Inc. and is geolocated to the United States.
TLS termination is performed by a Google Trust Services certificate issued to the WE1 organization, confirming the use of a publicly trusted certificate chain. An HTTP request to the root URL returns a 404 status code, suggesting the site is no longer serving content, and the current status is reported as taken offline. VirusTotal analysis recorded 14 detections out of 95 scanned security vendors, and the domain appears on a single security blocklist where it has been annotated by PhishDestroy as a brand‑impersonation vector. The page title retrieved from the host reads “Phantom Wallet – Connect Your Wallet – Phantom”, directly referencing the targeted brand and aligning with the classified “Crypto Scam” category.
No additional payload or malicious file hashes have been disclosed, and the available evidence is limited to infrastructure and branding attributes. Defenders should continue to block the resolved IP address and the domain name at network perimeter solutions, update URL‑filtering policies to include this FQDN, and monitor for future registrations that reuse the same Cloudflare name‑server pair or similar page titles referencing Phantom. Given the presence of multiple vendor detections and the confirmed brand impersonation, the domain merits an elevated risk rating until the underlying infrastructure is fully mitigated.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
التقنيات
حُدّدَت تقنيتان عاليتا الثقة
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب