jeremyrooks[.]com
“_im钱包官网-im钱包苹果下载”
This report analyzes the domain jeremyrooks.com, which is identified as a wallet drainer scam. The page title, "_im钱包官网-im钱包苹果下载", indicates the site impersonated the official website for the "im钱包" cryptocurrency wallet, specifically targeting users seeking an iOS (Apple) download. The primary threat is that the site would trick users into connecting their cryptocurrency wallets, allowing the threat actor to drain funds.
Technical evidence confirms the malicious nature of jeremyrooks.com. VirusTotal detected it by 19 out of 95 vendors. The domain was created on 2022-03-03 and registered through Gname.com Pte. Ltd. It resolves to IP address 178.236.38.1, located in Great Britain (GB) and hosted on Ipv4superhub. The site uses an SSL certificate from Let's Encrypt (R13). Its nameservers are a.share-dns.com, a4.share-dns.com, b.share-dns.net, and b4.share-dns.net. The domain is flagged by multiple blocklists, including ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, and CyRadar.
The current status of jeremyrooks.com is DOWN/OFFLINE. The GridinSoft trust score is 0 out of 100, and the domain risk score is 73 out of 100, indicating a high risk. The site is no longer accessible, but the domain remains flagged across security platforms due to its previous malicious activity.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | jeremyrooks.com |
phishing | Phishing Block |
| Cloudflare DNS | jeremyrooks.com |
malicious | Sinkholed |
| DNS4EU | jeremyrooks.com |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 4 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analysis
Evidence & External Reports
PD-20260322-E92D02 Recipient: abuse@ipv4superhub.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive