Skip to security report
Domain security and threat intelligence
wallet.validator.test.canton.obsidian.systems favicon

wallet.validator.test.canton.obsidian.systems

“Canton Network Wallet Application”

Threat verdict Critical 71/100 evidence score
Availability Last known active Latest stored reachability observation
VirusTotal detections: 3/89 Brand impersonation: Binance Last known active
Jun 15, 2026 Binance
Actions API
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 3. Exercise extreme caution — do not enter credentials or personal information.
Report overview

The domain wallet.validator.test.canton.obsidian.systems was registered on May 16 2026 through NameCheap, Inc.

The detailed PhishDestroy AI analysis below remains in English to preserve the original forensic record.

Evidence Summary

CRITICAL
Score
71/100

The domain wallet.validator.test.canton.obsidian.systems was registered on May 16 2026 through NameCheap, Inc. It resolves to the public IPv4 address 52.1.44.192, which belongs to an Amazon Web Services EC2 instance in the us‑east‑1 region. The hosting infrastructure is typical for short‑lived malicious deployments, leveraging AWS’s global DNS and compute resources to obtain a readily reachable endpoint. Infrastructure analysis shows the domain is delegated to four Amazon Route 53 name servers: ns-1861.awsdns-40.co.uk, ns-391.awsdns-48.com, ns-1084.awsdns-07.org, and a fourth entry truncated in the source data. The web server returns HTTP 200 for default requests and presents an Amazon‑issued RSA 2048‑M01 certificate, confirming the use of AWS Certificate Manager. Gridinsoft’s trust scoring assigns a rating of 0 / 100, indicating a reputation of extreme distrust. Threat intelligence classifies the site as a crypto‑drainer, a pattern that typically lures cryptocurrency wallet users into submitting private keys or signing malicious transactions. The domain appears on a single security blocklist and is currently blocked by PhishDestroy. VirusTotal analysis records a single positive detection out of 95 scanners, reinforcing the low‑visibility but high‑risk nature of the operation. The combination of a fresh registration, zero trust score, and a valid SSL certificate is consistent with a fast‑flux style fraud campaign. Defenders should add wallet.validator.test.canton.obsidian.systems to DNS blocklists and enforce outbound filtering for connections to the 52.1.44.192 address. Network telemetry should be inspected for anomalous HTTP 200 responses from the AWS region, and any credential submission to the domain must be treated as compromise. Continuous monitoring of the associated name servers is advised, as the attacker may shift the underlying IP address while retaining the same domain registration.

VirusTotal
VirusTotal
3 det.
URLScan
URLScan
TLS Certificate
Amazon / Amazon RSA 2048 M01
Age
4 mo
Observed status
Last known active 200
PhishDestroy
DestroyList
Listed
Data coverage VirusTotal 3 / 89 OTX no community references URLScan capture stored report URLScan verdict Analysis completed TLS valid certificate, 96d WHOIS 4 mo old Screenshot external capture

Threat Response Pipeline

Discovery
Checks
Reports
Availability
9/11

Public Blocklist Status

Evasion analysis

Cloaking & traffic-distribution check

Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.

Stored cloaking flag
Not observed
Cloaking score
0/6
Last cloaking scan
Server header seen by scanner
nginx/1.31.5

Scanner note: alive_content: raw=ok; http=200; via=https_proxy; server=nginx/1.31.5

Live TDS fingerprint check
Seven Keitaro fingerprints plus a crawler-versus-browser comparison, run from the PhishDestroy scanner when this section scrolls into view.
Waiting

Stored Capture · 1 source

Page Title
Canton Network Wallet Application
TLS Certificate
Valid transport encryption · Issued by Amazon / Amazon RSA 2048 M01 · valid for 96 days

Domain Intelligence

Domain
URLScan Verdict Analysis completed score 0 report ↗
Server / ASN nginx/1.29.0 · AS14618 Amazon.com, Inc.
IP Reputation abuse score 0/100 0 reports checked Sep 11, 2026
Registrar (base domain) NameCheap US(US)
IP Address 52.1.44.192 US
GeoUS Ashburn, US
NetworkAS14618 · AWS EC2 (us-east-1)
Registration (base domain)obsidian.systems · Created May 16, 2026 (126d)
HTTP Status200
Technical detailsDNS, SSL SANs, timestamps
First DetectedJun 15, 2026
DOM Analysisanalyzed Sep 19, 2026score 71/100
IoC Extractionscanned Sep 19, 20260 wallet · 0 Telegram IoCs
Nameserversns-721.awsdns-26.net
TLS Fingerprint
TLS Observationvalid from Nov 26, 2025scanned May 17, 2026
ICANN OVERSIGHT Registration: obsidian.systems

Accreditation and RAA context

Registrar accreditation and DNS abuse obligations

For the registrable domain obsidian.systems behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nothing is sent automatically.
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

3 / 89 security vendors flagged this domain
View on VT
Last analyzed First positive detection Previous stored snapshot: 2 detections
CRDF
Fortinet
Gridinsoft

Lookalike domains

187 stored lookalike domains

Show all (88)
binabce.com replacement binacne.com transposition binan.ce.com subdomain binancecom.com various binanci.com vowel-swap binanco.com vowel-swap binancr.com replacement binancs.com replacement binancw.com replacement binande.com replacement binanfe.com replacement binanve.com replacement binanxe.com replacement binnace.com transposition binonce.com vowel-swap binsnce.com replacement binunce.com vowel-swap binynce.com replacement binznce.com replacement bniance.com transposition bunance.com replacement ibnance.com transposition ninance.com replacement b-inance.com hyphenation b8inance.com insertion b8nance.com replacement b9nance.com replacement bbinance.com repetition bhinance.com insertion bi-nance.com hyphenation biance.com omission bibance.com replacement bibnance.com insertion bihance.com replacement bihnance.com insertion biinance.com repetition bijnance.com insertion biknance.com insertion bimance.com homoglyph bimnance.com insertion bin-ance.com hyphenation binaance.com repetition binabnce.com insertion binace.com omission binahce.com replacement binamnce.com insertion binan-ce.com hyphenation binanbce.com insertion binanc-e.com hyphenation binanc.com omission binanc3.com replacement binancce.com repetition binancve.com insertion binancxe.com insertion binancz.com replacement binandce.com insertion binane.com omission binanec.com homoglyph binanhce.com insertion binanmce.com insertion binannce.com homoglyph binanvce.com insertion binanxce.com insertion binarnce.com homoglyph binasnce.com insertion binawnce.com insertion binbance.com insertion binhance.com insertion binmance.com insertion binnance.com homoglyph binnce.com omission binqance.com insertion binsance.com insertion binwnce.com replacement binyance.com insertion bionance.com insertion birnance.com homoglyph biunance.com insertion bjnance.com replacement bnance.com omission bninance.com insertion boinance.com insertion bonance.com replacement buinance.com insertion bvinance.com insertion clinance.com homoglyph dinarce.com homoglyph ginance.com replacement

Showing 100 of 187

Community reports

Reported by 1 community member, first seen May 16, 2026

Stored reports
1
Unique reported URLs
1
Accepted1

Evidence & External Reports

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/wallet.validator.test.canton.obsidian.systems"
  title="PhishDestroy threat report for wallet.validator.test.canton.obsidian.systems"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>