magic-wallets.shop
“MagicWallet — Sign In”
magic-wallets.shop — Contenuto non disponibile. Simulazione del marchio: Unknown; Tipo di truffa: Impersonation. Riepilogo delle prove: VirusTotal 8/90 (alphaMountain.ai, BitDefender, CRDF, Fortinet, G-Data); URLScan capture; Spamhaus DBL_PHISH; PhishDestroy score 75/100. Registrar: GNAME.COM.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Riepilogo delle prove
PhishDestroy first observed magic-wallets.shop on Aug 26, 2026. Stored content metadata identifies Unknown as the apparent target. The captured page title is “MagicWallet — Sign In”. Stored page analysis classifies the content as impersonation. Current evidence score: 75/100 (critical).
Positive findings are stored from 2 sources: VirusTotal and Spamhaus DBL. VirusTotal recorded 8 detections among 90 engines: alphaMountain.ai, BitDefender, CRDF, Fortinet, G-Data, Kaspersky, PhishFort, SOCRadar on Sep 4, 2026 at 19:12 UTC. Spamhaus DBL: DBL_PHISH on Sep 4, 2026 at 02:30 UTC. Non-positive and contextual checks: AlienVault OTX listed 4 community pulse references (not vendor detections) on Sep 4, 2026 at 19:14 UTC. The separate external-blocklist snapshot contained no matches on Sep 21, 2026 at 10:20 UTC. Google Safe Browsing returned no flag on Sep 4, 2026 at 19:13 UTC. A URLScan capture is available, but no capture timestamp was recorded.
No conclusive timestamped HTTP response is stored. Registration records for the domain list GNAME.COM PTE. LTD. as the registrar. At collection time, the hostname resolved to 172.67.133.228 on AS13335 (Cloudflare, Inc.). The IP and ASN identify shared Cloudflare edge infrastructure; the origin server is not established by this address. The evidence archive retains 1 visual capture from URLScan.
The content indicators and 2 positive source findings support the current Unknown-themed impersonation classification.
Informazioni sulla sicurezza di rete
Forensic History & Detection Timeline
-
Domain Status Transition Sep 8, 2026 · 12:00 UTCDomain state transitioned from alive to dead.
-
VirusTotal Detections Update Sep 4, 2026 · 04:43 UTCVirusTotal scanner detections updated from 7 to 8. Added scanner alerts: CRDF.
-
Threat First Observed Sep 4, 2026 · 01:03 UTCDomain ingestion complete. Initial state is marked as alive.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not yet scanned
- Last cloaking scan
Scanner note: dns_error: raw=dns_error; via=local_dns_prefilter
Acquisizione salvata · 1 source
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Intelligence della comunità
1 segnalazione della comunità
CategoriaIMPERSONATION
Phishing: credential harvesting, impersonation, impersonating Magic
Dati e relazioni esterne
“Phishing: credential harvesting, impersonation, impersonating Magic”
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo