imtaken[.]cc
“imToken official website|Ethereum and Bitcoin blockchain wallet”
imtaken.cc — असत्यापित. ब्रांड प्रतिरूपण: Arbitrum; घोटाले का प्रकार: Crypto Scam. साक्ष्य सारांश: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, Bfore.Ai PreCrime, BitDefender, Chong Lua Dao); URLScan malicious verdict; PhishDestroy score 95/100.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain imtaken.cc was registered on 21 February 2026 and is presently hosted on the IP address 20.247.100.105, which resolves to a Microsoft Corporation network (AS8075) located in Hong Kong. The site’s TLS certificate is identified as R13, indicating a publicly trusted certificate without obvious anomalies. The page title returned from the HTTP response reads "imToken official website|Ethereum and Bitcoin blockchain wallet", a clear reference to the imToken cryptocurrency wallet service, while the threat intelligence tags list the brand target as Arbitrum. This mismatch between the page title and the claimed impersonated brand suggests a deliberate brand‑impersonation tactic aimed at users of the Arbitrum ecosystem.
Open‑source threat feeds corroborate the malicious nature of the domain. AlienVault OTX includes the domain in one pulse, and VirusTotal reports that 20 of 93 security vendors classify the host as malicious, a proportion that exceeds typical background noise for benign sites. The domain appears on a single security blocklist and is explicitly blocked by the PhishDestroy service, reinforcing the assessment that it is being used for a crypto‑related scam. The current HTTP status is reported as offline, meaning the site is not presently serving content, which limits real‑time verification of the exact payload but does not negate the historical evidence of abuse.
Defenders should continue to block imtaken.cc at the DNS and proxy layers, and add the associated IP range to network‑level deny lists. Because the infrastructure resides on a Microsoft‑owned AS, contacting the provider’s abuse team with the full set of indicators (domain name, IP address, registration date, detection counts, and blocklist references) may expedite takedown. Continuous monitoring of passive DNS and certificate transparency logs is advised to detect any re‑registration or reuse of the same IP address by related threats.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।