Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
imtokens[.]co
“imToken official website|Ethereum and Bitcoin blockchain wallet”
Riepilogo delle prove
Analysis confirms that imtokens.co is an active generic phishing site targeting cryptocurrency users. The domain was registered on February 21, 2026 and currently resolves to IP 20.247.100.105, which geolocates to Hong Kong and is announced by AS8075, a Microsoft Corporation network. The hosting server presents an HTTP 200 response and serves a page whose title reads "imToken official website|Ethereum and Bitcoin blockchain wallet," indicating an attempt to masquerade as a legitimate wallet service. The site employs Ant Design and Nginx, with Clicky analytics detected, and is protected by a certificate from a publicly trusted certificate authority. Security telemetry shows 22 of 93 VirusTotal scanners flag the domain, and it appears on three external phishing blocklists. The domain is listed by multiple blocklist providers and has a Gridinsoft trust score of 0/100. Defenders should block the domain and its resolved IP at the network perimeter, monitor DNS queries for the listed CloudNS nameservers, and add the host to local threat intel feeds. Ongoing observation is advised to detect any changes in hosting or content, as current evidence is limited to infrastructure and title metadata.
Istantanea delle prove inviate
- Inviato
- Voci del registro
- 1
- ID del caso
PD-20260204-14E682- Titolo della pagina acquisita
- imToken official website|Ethereum and Bitcoin blockchain wallet
- Artefatto PDF
- Prova in PDF
Base giuridica
Testo completo delle prove
Acceptable Use Policy (AUP): The domain imtokens.co is engaged in phishing activities, which directly contravenes the AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The continued operation of this domain constitutes a violation of the TOS, which reserves the right to suspend or terminate services for any activities that promote fraud or phishing.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. law prohibits unauthorized access to computers and networks, which is relevant as phishing schemes often involve unauthorized data access.
Wire Fraud Statute: This law makes it illegal to use electronic communications to commit fraud, which applies to the fraudulent activities conducted via imtokens.co.
Anti-Phishing Act: This legislation specifically targets phishing schemes and imposes penalties for those who engage in such deceptive practices.
Regulatory Note: Failure to take immediate action against the domain imtokens.co may result in liability for facilitating illegal activities and could lead to regulatory scrutiny or legal action. Compliance with your AUP and TOS is imperative to avoid potential repercussions.
Data Coverage
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | imtokens.co |
malicious | Sinkholed |
| OpenDNS | imtokens.co |
phishing | Phishing Block |
| Hagezi Threat Feed | imtokens.co |
malicious | Sinkholed |
| DigiCert UltraDNS | imtokens.co |
malicious | Sinkholed |
| DNS4EU | imtokens.co |
malicious | Sinkholed |
| Quad9 DNS | imtokens.co |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
8 fonti esterne monitorate Nessuna corrispondenza
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of imtokens.co · checked Mar 1, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo