Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
imtoken[.]xn--fiqs8s
“530”
Zusammenfassung der Beweislage
imtoken.xn--fiqs8s was registered on 21 February 2026 through the registrar 成都西维数码科技有限公司. The domain is configured with the authoritative nameservers ns1.363.hk and ns2.363.hk and resolves to the IPv4 address 45.205.26.173, which belongs to AS8796 FASTNET DATA INC and is geolocated in the United States. No TLS certificate is presented for the host, indicating that connections are served over plain HTTP only. The page title retrieved during the brief scan is the string “530”, providing no further context about the page’s purpose. VirusTotal analysis shows that seven of ninety‑three antivirus and URL scanning engines flagged the domain as malicious, and Gridinsoft assigned a trust score of zero out of one hundred.
The domain is listed on a single external security blocklist and has been actively blocked by the PhishDestroy service. Intelligence tags the site as a crypto‑related scam that impersonates the brand “celer”, aligning with the broader threat category of brand impersonation. Current operational status is reported as offline, suggesting that the hosting infrastructure has been taken down or is no longer serving content at the time of observation. The available evidence confirms that the infrastructure is deliberately associated with a brand‑impersonation campaign targeting users of the celer brand, likely to harvest cryptocurrency credentials or funds.
However, the lack of a TLS certificate, the minimal page title, and the relatively low number of vendor detections leave open questions about the full scope of the malicious payload and whether additional phishing pages exist under the same IP address. Defenders should add 45.205.26.173 to network‑level deny lists, enforce DNS filtering for imtoken.xn--fiqs8s, and monitor the associated nameservers (ns1.363.hk, ns2.363.hk) for any re‑registration activity.
Momentaufnahme der übermittelten Beweise
- Gesendet
- Protokolleinträge
- 1
- Fall-ID
PD-20260203-C94F64- Titel der erfassten Seite
- imToken 官网|以太坊和比特币区块链钱包
- PDF-Artefakt
- PDF-Beweis
Rechtsgrundlage
Vollständiger Beweistext
Acceptable Use Policy (AUP): The domain imtoken.xn--fiqs8s is engaged in phishing activities, which directly contravenes the AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The registrar reserves the right to suspend or terminate services for violations of the TOS, which includes the operation of domains facilitating phishing schemes.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, which is applicable to phishing activities.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals through electronic communications, including phishing.
Anti-Phishing Act (15 U.S.C. § 7704): This act prohibits the use of misleading information in electronic communications, which is a fundamental characteristic of phishing operations.
Regulatory Note: Failure to take immediate action against this domain may expose your organization to legal liabilities and regulatory scrutiny. Non-compliance with your own AUP and TOS could result in further legal repercussions.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | imtk9lc.com |
malicious | Sinkholed |
| DNS4EU | imtk9lc.com |
malicious | Sinkholed |
| Cloudflare DNS | 02458454xyz.imtoken1.bmxuij.cn |
malicious | Sinkholed |
| OpenDNS | 02458454xyz.imtoken1.bmxuij.cn |
phishing | Phishing Block |
| DNS4EU | 02458454xyz.imtoken1.bmxuij.cn |
malicious | Sinkholed |
| Cloudflare DNS | vccxrfo3.imtoken.bmxuij.cn |
malicious | Sinkholed |
| OpenDNS | vccxrfo3.imtoken.bmxuij.cn |
phishing | Phishing Block |
| DNS4EU | vccxrfo3.imtoken.bmxuij.cn |
malicious | Sinkholed |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 13.08.2026
Erkennungszeitleiste
-
Domainstatus
Erreichbar → Nicht erreichbar
-
Domainstatus
Erreichbar → Nicht erreichbar
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
Domainstatus
Nicht erreichbar → Erreichbar
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt