imtoken-wallet[.]org[.]cn
“imToken Download - imToken Wallet | Leading Digital Asset Wallet”
Riepilogo delle prove
Analysis of imtoken-wallet.org.cn indicates an active brand‑impersonation campaign targeting Discord users. The domain was registered on February 21, 2026 through Dominet (HK) Limited and resolves to IP address 38.6.207.3, which is hosted in the United States under ASN 398823 (PEG TECH INC). Network fingerprints show the web server runs Nginx with HTTP/3 enabled and enforces HSTS, while the TLS certificate is issued by Let’s Encrypt (R12). An HTTP request returns status 200 and the page title reads "imToken Download - imToken Wallet | Leading Digital Asset Wallet", suggesting the site is masquerading as a cryptocurrency wallet downloader.
The campaign is classified as Wallet/Seed Phishing and explicitly lists Discord as the impersonated brand. VirusTotal scans report five of ninety‑three security vendors flagging the domain, and PhishDestroy has already blocked it; the domain appears on one additional security blocklist. Reputation services give the domain a Gridinsoft trust score of zero out of one hundred, reinforcing its malicious nature.
Nameservers ns7.alidns.com and ns8.alidns.com are in use, consistent with typical fast‑flux techniques. Defenders should add imtoken-wallet.org.cn to web‑filter and DNS blocklists, monitor outbound traffic for connections to 38.6.207.3, and enforce strict URL filtering for any attempts to download cryptocurrency wallet software. Continuous re‑evaluation of the domain’s status is advised, given its recent registration date and active infrastructure.
Istantanea delle prove inviate
- Inviato
- Voci del registro
- 1
- ID del caso
PD-20260203-82053E- Titolo della pagina acquisita
- imToken Download - imToken Wallet | Leading Digital Asset Wallet
- Artefatto PDF
- Prova in PDF
Base giuridica
Testo completo delle prove
Section 3.1 of AUP: The domain imtoken-wallet.org.cn is engaged in phishing activities, misleading users into providing sensitive information under false pretenses.
Section 4.2 of TOS: The registrar reserves the right to suspend services for any illegal activities, which includes the operation of fraudulent websites.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): Prohibits unauthorized access to computers and the use of fraud to obtain information.
Wire Fraud Statute (18 U.S.C. § 1343): Criminalizes schemes to defraud individuals or entities via electronic communications.
CAN-SPAM Act (15 U.S.C. § 7701): Regulates commercial email and prohibits deceptive practices in electronic communications.
Regulatory Note: Failure to act on this report may expose your organization to liability under applicable laws and could result in regulatory scrutiny. Immediate action is recommended to mitigate potential legal repercussions.
Data Coverage
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | imtoken-wallet.org.cn |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Stato del dominio
Raggiungibile → Non raggiungibile
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
-
Stato del dominio
Raggiungibile → Non raggiungibile
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo