wap[.]imtoken-safe[.]com
Pemeriksaan phishing dan keamanan wap.imtoken-safe.com
“404 Not Found”
wap.imtoken-safe.com — Konten tidak tersedia (HTTP 502). Jenis penipuan: Crypto Scam. Ringkasan bukti: VirusTotal 17 detections (engine total unavailable) (ADMINUSLabs, Criminal IP, BitDefender, Cluster25, CRDF); URLQuery 10 alerts; CF Radar malicious; PhishDestroy score 95/100. Registrar: Dominet (HK).
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Analysis indicates wap.imtoken-safe.com is a high-risk brand impersonation domain designed to deceive users by mimicking OKX-related services. The observed infrastructure suggests a credential theft or session-hijacking attempt targeting cryptocurrency account holders. The page resolves inconsistently to a 404 Not Found response, which may indicate takedown or defensive sinkholing after detection.
Technical evidence confirms malicious classification. VirusTotal reports 17/95 security vendors flagging the domain as malicious. The domain was created on March 08, 2026 and registered through Dominet (HK) Limited. It resolves to IP 107.151.68.90, hosted in Hong Kong under AS132839 POWER LINE DATACENTER. The domain appears on 1 security blocklist and is explicitly blocked by PhishDestroy. SSL is issued via Let's Encrypt / R12, indicating automated certificate provisioning commonly seen in rapid deployment phishing infrastructure.
If users interacted with this domain, any credentials or wallet-related data entered should be treated as compromised. Immediate steps include revoking active sessions, rotating passwords, and transferring assets from affected accounts where applicable. Browser sessions should be cleared, and any extensions installed or permissions granted during interaction should be reviewed for unauthorized access. Endpoint scans are recommended to detect potential credential-stealing scripts or injected payloads. Due to confirmed 17/95 detection rate and active impersonation of a cryptocurrency platform, the domain presents elevated risk of account takeover and financial loss.
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | www.imtoken-safe.com |
malicious | Sinkholed |
| Cloudflare DNS | www.imtoken-safe.com |
malicious | Sinkholed |
| OpenDNS | www.imtoken-safe.com |
phishing | Phishing Block |
| DNS4EU | www.imtoken-safe.com |
malicious | Sinkholed |
| Quad9 DNS | www.imtoken-safe.com |
malicious | Sinkholed |
| DNS4EU | wap.imtoken-safe.com |
malicious | Sinkholed |
| Cloudflare DNS | wap.imtoken-safe.com |
malicious | Sinkholed |
| Quad9 DNS | wap.imtoken-safe.com |
malicious | Sinkholed |
| DigiCert UltraDNS | wap.imtoken-safe.com |
malicious | Sinkholed |
| OpenDNS | wap.imtoken-safe.com |
phishing | Phishing Block |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Registration: imtoken-safe.com
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain imtoken-safe.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknologi · 2 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Analisis VirusTotal
Bukti Terarsip
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of wap.imtoken-safe.com · checked Mar 10, 2026
Bukti & Laporan Eksternal
PD-20260308-69B141 Recipient: domainabuse@service.aliyun.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive