imtoken[.]android-zh-cn[.]com
Análisis de phishing y seguridad de imtoken.android-zh-cn.com
“imToken | Ethereum & Bitcoin Wallet”
imtoken.android-zh-cn.com — error del servidor (HTTP 502). Suplantación de marca: Across; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VT 8/91 (BitDefender, CyRadar, ESET, Fortinet, G-Data); URLQuery 4 alerts; URLScan malicious; GSB no flag; BL 0; PD 78/100. Registrador: Gname.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
imtoken.android-zh-cn.com is a subdomain of android-zh-cn.com. PhishDestroy first observed the hostname on Feb 3, 2026. Stored content metadata identifies Across as the apparent target. The captured page title is “imToken | Ethereum & Bitcoin Wallet”. Page analysis recorded additional brand references to Discord, Ethereum, and Ton. Stored page analysis classifies the content as crypto scam. Current evidence score: 78/100 (critical).
Positive findings are stored from 3 sources: VirusTotal, URLQuery, and URLScan. VirusTotal recorded 8 detections among 91 engines: BitDefender, CyRadar, ESET, Fortinet, G-Data, Gridinsoft, Sophos, Webroot on Aug 2, 2026 at 02:15 UTC. URLQuery recorded 4 threat-system alerts on Feb 3, 2026 at 21:53 UTC. URLScan returned a malicious verdict with score 100; scan metadata linked the capture to Imtoken and assigned phishing as its category on Jul 29, 2026 at 03:26 UTC. Non-positive and contextual checks: The external blocklist snapshot contained no matches on Aug 8, 2026 at 02:20 UTC. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC.
HTTP 502 server error was recorded on Aug 7, 2026 at 22:14 UTC. Registration records for the registrable domain android-zh-cn.com list Gname.com Pte. Ltd. as the registrar. At collection time, the hostname resolved to 18.162.53.8 on AS16509 (Amazon.com, Inc.). The IP and ASN identify shared CDN edge infrastructure; the origin server is not established by this address. The stored server header is nginx. DOM analysis on Apr 23, 2026 at 03:23 UTC returned 10/100. The evidence archive retains 3 visual captures from PhishDestroy, URLScan, and URLQuery.
The content indicators and 3 positive source findings support the current Across-themed crypto scam classification.
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | imtoken.android-zh-cn.com |
malicious | Sinkholed |
| OpenDNS | imtoken.android-zh-cn.com |
phishing | Phishing Block |
| DNS4EU | imtoken.android-zh-cn.com |
malicious | Sinkholed |
| Quad9 DNS | imtoken.android-zh-cn.com |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Registration: android-zh-cn.com
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain android-zh-cn.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.