phantomfix[.]netlify[.]app
phantomfix.netlify.app की फ़िशिंग और सुरक्षा जाँच
“Phantom — Crypto & NFT Wallet — Solana | Ethereum | Polygon”
phantomfix.netlify.app — सामग्री अनुपलब्ध (HTTP 404). ब्रांड प्रतिरूपण: Phantom; घोटाले का प्रकार: Crypto Scam. साक्ष्य सारांश: VirusTotal 13/95 (ADMINUSLabs, ChainPatrol, Criminal IP, alphaMountain.ai, BitDefender); PhishDestroy score 89/100. रजिस्ट्रार: Netlify.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
phantomfix.netlify.app was observed hosting a page whose title reads “Phantom — Crypto & NFT Wallet — Solana | Ethereum | Polygon”, indicating an attempt to impersonate the Phantom cryptocurrency wallet. The domain is served via Netlify, as evidenced by the hosting provider tag and the presence of a Netlify‑generated TLS certificate issued by DigiCert Global G2. The certificate is valid for the domain and includes the standard DigiCert chain, confirming that the TLS handshake completes without certificate errors. An IPv6 address 2a05:d014:58f:6200::259 resolves to the domain; the address belongs to Amazon’s AS16509 network and geolocates to Germany, typical of Netlify’s edge infrastructure.
HTTP requests return a 404 status, suggesting the original content has been removed or the site is no longer serving the malicious page. VirusTotal reports that 13 of 95 scanners flagged the domain, indicating a moderate level of detection across anti‑malware engines. The domain appears on a single external blocklist and is listed as blocked by PhishDestroy, reinforcing its classification as malicious. The page title and the “Crypto Scam” label in the intelligence point to a financial fraud campaign targeting users of the Phantom wallet, likely attempting to harvest private keys or lure victims into fraudulent token transactions.
No additional indicators such as phishing form URLs, JavaScript payloads, or credential‑stealing scripts were captured in the available data, leaving the exact attack vector uncertain. Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any resurgence of the address, and incorporate the observed TLS fingerprint and IPv6 prefix into threat‑intel feeds. Organizations using Phantom should educate users about unsolicited requests for wallet access and advise verification of URLs before any credential entry.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 2 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 100% विश्वासHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% विश्वासवायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।