get--phantom-wallet--faq[.]typedream[.]app
“Phantom Wallet® (en-US) | Ledger Support”
get--phantom-wallet--faq.typedream.app — Contenido no disponible. Suplantación de marca: Phantom; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 14/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CRDF); Google Safe Browsing flagged; PhishDestroy score 92/100. Registrador: Cloudflare.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain get--phantom-wallet--faq.typedream.app was observed serving a page titled "Phantom Wallet® (en-US) | Ledger Support," directly referencing the Phantom brand. Infrastructure analysis shows the site was hosted on Cloudflare, Inc. and resolved to IP address 188.114.97.3, which belongs to AS13335 (Cloudflare) and is geolocated in the United States. The TLS certificate presented was issued by Google Trust Services under the WE1 authority, indicating use of Google‑managed HTTPS. HTTP probing returned a 404 status code, and the domain’s nameservers could not be retrieved (NS_NOT_FOUND).
Technical fingerprinting identified a stack consisting of Node.js, React, Next.js, Google Cloud services (Trace and CDN), Webpack, and Cloudflare as the service edge. Viral detection data from VirusTotal recorded that 14 of 95 scanning vendors flagged the domain as malicious. Google Safe Browsing classified the site under social engineering, and the domain appears on one external security blocklist. PhishDestroy has already taken the domain offline, and current status is reported as offline.
The activity is categorized as a crypto‑related scam employing brand impersonation of Phantom. Defenders should immediately block the domain and its resolving IP at perimeter firewalls and proxy filters, update URL and hash based detection rules to include the observed page title, and monitor for additional subdomains under typedream.app that may use similar technology stacks. Continuous monitoring of Cloudflare‑hosted assets for suspicious brand references is advised, as well as periodic re‑scanning of the IP range for resurgence of malicious content.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 9 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100 % de confianzaReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100 % de confianzaNext.js is a React framework for developing single page Javascript applications.
nextjs.org 100 % de confianzaGoogle Cloud Trace is a distributed tracing system that collects latency data from applications and displays it in the Google Cloud Console.
cloud.google.com 100 % de confianzaCloud CDN uses Google's global edge network to serve content closer to users.
cloud.google.com 100 % de confianzaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % de confianzaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % de confianzaAnálisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.