phe-ntom-wallet[.]pages[.]dev
“Connecting the Phantom Wallet to Your Project - DEV Community®”
Gespeicherte Beobachtung
Beobachteter Titelkontrast
Zusammenfassung der Beweislage
The domain phe-ntom-wallet.pages.dev was created on February 21, 2026 and is registered through Cloudflare, Inc. Infrastructure analysis shows it is served via Cloudflare’s edge network (AS13335) with a public IP of 172.66.44.103 located in the United States. The site enforces HSTS and supports HTTP/3, indicating a modern web stack, but these features do not attest to legitimacy. TLS termination is provided by a Google Trust Services certificate (WE1), which is commonly used for Cloudflare‑proxied sites and therefore cannot be used as a trust indicator. The page title returned from the site is "Connecting the Phantom Wallet to Your Project - DEV Community®," a phrase unrelated to the claimed target brand, Discord, suggesting an attempt to lure users interested in cryptocurrency wallets while impersonating Discord for social engineering.
The domain is currently offline and returns HTTP 403, yet it was previously detected by one of 93 VirusTotal scanners and appears on the PhishDestroy blocklist, confirming it as a known malicious indicator. Gridinsoft assigned a trust score of 0 / 100, reinforcing the high‑risk assessment. The domain impersonates Discord and is categorized as a crypto scam, but no additional payload or phishing page content has been captured, leaving the exact user‑facing tactics uncertain.
Defenders should immediately block phe-ntom-wallet.pages.dev at perimeter and endpoint filters, add the domain to URL allow‑list exclusions, and monitor DNS queries for any resurgence. Enriching internal threat feeds with the observed indicator values (creation date, IP, SSL issuer, blocklist status) will improve detection of future attempts that reuse the same infrastructure. Continuous re‑scanning is advised in case the site becomes active again, as the current 403 response may hide malicious content that could be revealed when the site is restored.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
Erkennungszeitleiste
-
Domainstatus
Erreichbar → Nicht erreichbar
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
Forensische Erkenntnisse
Technologien
3 Technologien mit hoher Konfidenz erkannt
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of phe-ntom-wallet.pages.dev · checked Apr 12, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt