phantom-veil[.]ru
“Voordat u doorgaat”
Ringkasan bukti
Analysis on July 24, 2026 indicates that the domain phantom-veil.ru is currently offline but was previously identified as part of a crypto‑scam campaign impersonating the brand Phantom. The domain resolved to the IP address 142.250.184.238, which belongs to Google LLC (AS15169) and is geolocated to the United States. DNS records show six nameservers under the beget.* hierarchy (ns1.beget.com, ns1.beget.pro, ns1.beget.ru, ns2.beget.com, ns2.beget.pro, ns2.beget.r), suggesting the domain was hosted on a shared hosting platform. Registration was performed through VDSINA, associated with ASN 216071. No SSL certificate was observed, meaning any traffic would have been transmitted over plain HTTP.
The only visible page title retrieved before takedown was “Voordat u doorgaat”, which does not provide direct evidence of the malicious payload but aligns with the typical practice of using language‑agnostic prompts to advance the user flow. VirusTotal scanned the domain and five out of ninety‑five security vendors flagged it as malicious, reinforcing the suspicion of malicious intent. Gridinsoft assigned a trust score of 0 out of 100, and the domain appears on at least one external blocklist. PhishDestroy listed the domain as blocked, and the current status is noted as taken offline. The combination of a low trust score, multiple vendor detections, and inclusion on a blocklist indicates a high likelihood that the domain was used to lure victims into a cryptocurrency‑related fraud.
Uncertainties remain regarding the specific phishing kit or the exact content served before the takedown, as no screenshots or detailed page analysis are available. The absence of an SSL certificate also prevents verification of any potential credential capture mechanisms. Defenders should continue to monitor the IP address 142.250.184.238 for residual activity, enforce outbound filtering to block connections to this address, and add phantom-veil.ru to internal blocklists.
Data Coverage
Alur Tanggapan Ancaman Pipeline
Cakupan daftar blokir
10 sumber eksternal dipantau · snapshot tersimpan 11/08/2026
Linimasa deteksi
-
Cloudflare Radar
Pemindaian Cloudflare Radar tersimpan · Buka pemindaian
Analisis VirusTotal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive