blockchain[.]com[.]toba[.]cn[.]com
“Blockchain Wallet Official Shop”
Résumé des preuves
This domain, blockchain.com.toba.cn.com, is flagged as an active high-risk brand impersonation targeting Blockchain.com, a known cryptocurrency wallet provider. Infrastructure analysis reveals the domain resolves to 95.129.233.223, an IP address geolocated in Russia and associated with AS57724 (DDOS-GUARD LTD), a network frequently linked to malicious hosting. The SSL certificate is issued by DDoS-Guard, a provider commonly observed in phishing and scam infrastructure. The domain's nameservers are operated by CentralNic, a legitimate registry, but this does not mitigate the observed abuse. The page title, 'Blockchain Wallet Official Shop,' directly aligns with the reported scam type (crypto scam), indicating an intent to deceive users into believing the site is affiliated with Blockchain.com. The domain is currently returning an HTTP 503 status, which may suggest temporary takedown efforts, evasion tactics, or infrastructure issues, but it remains active and unblocked by most security vendors. As of the latest scan, only one of 95 security vendors on VirusTotal flags this domain, though this low detection rate does not confirm safety. The domain appears on one security blocklist, specifically PhishDestroy. Registration details point to Instra Corporation Pty Ltd as the registrar, a provider previously associated with abusive domains. Defenders should treat this domain as malicious and prioritize blocking or monitoring its resolution and SSL certificate. Given the HTTP 503 status, further investigation into related infrastructure (IP, nameservers, registrar) is recommended to identify additional threats. The exact content and functionality of the site remain unanalyzed, but the available indicators strongly suggest a crypto-focused scam operation.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 13/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
État du domaine
Accessible → Inaccessible
-
État du domaine
Accessible → Inaccessible
-
État du domaine
Accessible → Inaccessible
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Signalements communautaires
Signalé par 1 membre de la communauté ; première observation le 20/08/2025
- Signalements enregistrés
- 1
- URL signalées uniques
- 1
Analyse VirusTotal
Preuves archivées
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif