phantom-wallet[.]duckdns[.]org
“phantom-wallet.duckdns.org”
phantom-wallet.duckdns.org — Non vérifié. Usurpation de l'identité de la marque : Across; Type d'arnaque : Wallet/seed Phishing. Résumé des preuves: VirusTotal 15/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); URLScan malicious verdict; PhishDestroy score 95/100. Bureau d’enregistrement: DuckDNS.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, phantom-wallet.duckdns.org, is flagged for brand impersonation, a high-risk threat where malicious actors create a website that mimics a legitimate brand to deceive users. The impersonation is designed to trick visitors into revealing sensitive information or performing actions that could compromise their security.
Analysis indicates that phantom-wallet.duckdns.org was created on February 21, 2026, and has been flagged by 14 out of 95 security vendors on VirusTotal. The domain is registered through DuckDNS, a free dynamic DNS service, which can be a red flag as it is often used for temporary or illicit activities. Additionally, the domain resolves to an IP address, 103.186.31.94, located in Indonesia and is associated with AS141892 CV Andhika Pratama Sanggoro. The site also appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL, further confirming its malicious nature.
If a user has visited this site, they should take immediate steps to ensure their security. First, they should change any passwords or sensitive credentials that may have been entered on the site. Users are advised to monitor their accounts for any unauthorized activity and to enable two-factor authentication (2FA) for added security. It is also recommended to run a full system scan using reputable antivirus software to detect and remove any potential malware. Users should report the incident to the legitimate brand, across, and to their respective financial institutions if any financial information was compromised.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif