imtoken-upay[.]com
“imToken official website|Ethereum and Bitcoin blockchain wallet”
साक्ष्य सारांश
Analysis of imtoken-upay.com, observed as an offline malicious site, confirms it is being used for wallet/seed phishing targeting users of the Arbitrum ecosystem. The domain was registered on 21 February 2026 through Dominet (HK) Limited and is serviced by four authoritative name servers (ns1.domainnamedns.com, ns2.domainnamedns.com, ns3.domainnamedns.com, ns4.domainname). No TLS certificate is presented, and HTTP requests return no valid response, consistent with the reported offline status. DNS resolution points to IP 20.247.100.105, which is hosted in Hong Kong under ASN 132839 (POWER LINE DATACENTER).
The hosting provider and geographic location are consistent with other infrastructure observed in recent crypto‑phishing campaigns. Reputation data show a Gridinsoft trust score of 0 / 100 and the domain appears on a single security blocklist. PhishDestroy has already blocked the host, and 16 of 95 security vendors on VirusTotal flag the domain as malicious, reinforcing the suspicion of illicit activity.
The page title returned by the site, “imToken official website|Ethereum and Bitcoin blockchain wallet”, is unrelated to the claimed target brand Arbitrum, indicating a deliberate brand‑impersonation tactic to lure victims. Given the convergence of registrar information, low trust score, blocklist inclusion, and multi‑vendor detections, defenders should immediately add imtoken-upay.com to network and endpoint block lists, monitor DNS queries for the four listed name servers, and enforce email and web filtering rules that flag any references to the brand Arbitrum originating from this domain. Continuous re‑evaluation is advised in case the site returns online, as the current offline state does not preclude future activation.
भेजे गए प्रमाण का स्नैपशॉट
- भेजा गया
- लेज़र रिकॉर्ड
- 1
- केस आईडी
PD-20260203-4F6E35- कैप्चर किए गए पेज का शीर्षक
- imToken official website|Ethereum and Bitcoin blockchain wallet
- PDF दस्तावेज़
- PDF प्रमाण
प्रमाण का पूरा पाठ
Acceptable Use Policy (AUP): The domain imtoken-upay.com is engaged in phishing activities, which directly contravenes the AUP by facilitating fraud and deception against unsuspecting users.
Terms of Service (TOS): The registrar reserves the right to suspend or terminate services for violations. The ongoing operation of this domain constitutes a clear violation of these terms, warranting immediate action.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): Prohibits unauthorized access to computers and networks, which is applicable as phishing schemes typically involve deceptive practices to gain sensitive information.
Wire Fraud Statute (18 U.S.C. § 1343): Criminalizes schemes to defraud individuals or entities through electronic communications, which is relevant given the fraudulent nature of phishing.
CAN-SPAM Act (15 U.S.C. § 7701): Regulates commercial email and prohibits misleading headers and deceptive subject lines, both of which are often employed in phishing attacks.
Regulatory Note: Failure to take appropriate action against this domain may expose your organization to legal liabilities and regulatory scrutiny. Immediate compliance with your AUP and TOS is essential to mitigate potential risks.
Data Coverage
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | imtokens.co |
malicious | Sinkholed |
| Cloudflare DNS | imtokens.co |
malicious | Sinkholed |
| Quad9 DNS | imtokens.co |
malicious | Sinkholed |
| DNS4EU | imtokens.co |
malicious | Sinkholed |
| OpenDNS | m.imtoken-upay.com |
phishing | Phishing Block |
| DNS4EU | m.imtoken-upay.com |
malicious | Sinkholed |
| OpenDNS | imtoken-upay.com |
phishing | Phishing Block |
| DNS4EU | imtoken-upay.com |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026
पहचान समयरेखा
-
Cloudflare Radar
Cloudflare Radar स्कैन संग्रहीत · स्कैन खोलें
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।