Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@v-sys.org.
The latest stored availability evidence still shows the domain reachable; 7 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
mtoken-im[.]cv
Verifica phishing e sicurezza per mtoken-im.cv
“imToken | Ethereum & Bitcoin Wallet”
mtoken-im.cv — Ultimo attivo conosciuto (HTTP 200). Simulazione del marchio: Ethereum; Tipo di truffa: Impersonation. Riepilogo delle prove: VirusTotal 22/91 (Criminal IP, alphaMountain.ai, BitDefender, Cluster25, CRDF); URLQuery 3 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. Registrar: Gname.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
This domain, mtoken-im.cv, was registered through the Gname registrar on July 28 2026 and is currently active. DNS resolution points to the single IPv4 address 176.97.124.73, served by the authoritative name servers a.share-dns.com, a1.share-dns.com, b.share-dns.net, and b1.share-dns.net. The domain appears on two public security blocklists and is actively listed by PhishDestroy and OpenPhish, indicating that the infrastructure is already recognized as malicious. VirusTotal reports that 17 of 91 scanning engines have flagged the domain, providing additional confirmation of its suspicious nature.
No public page title, SSL certificate details, or HTTP response codes have been disclosed, so the exact content and delivery mechanisms remain unknown. The lack of visible brand references or a known phishing kit prevents attribution to a specific campaign, but the classification as a generic phishing operation is supported by the blocklist entries. Defenders should prioritize immediate containment: add mtoken-im.cv and its resolving IP 176.97.124.73 to perimeter deny lists, enforce DNS sinkholing, and ensure that email gateways block any messages containing the domain.
Continuous monitoring of DNS queries for the four name servers can reveal additional infrastructure expansions. Because the domain is newly created, threat actors may still be testing delivery vectors; therefore, security teams should also watch for new variants that reuse the same name servers or IP range. Incident response teams should collect any observed traffic logs that reference the domain for deeper forensic analysis, and threat‑intel feeds should be updated to reflect the current detection counts and blocklist status.
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | mtoken-im.cv |
malicious | Sinkholed |
| DigiCert UltraDNS | mtoken-im.cv |
malicious | Sinkholed |
| DNS4EU | mtoken-im.cv |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Riscontro delle informazioni sulle minacce · source references
Tecnologie · 5 identified
Ant Design is a UI library that can be used with data flow solutions and application frameworks in any React ecosystem.
ant.design Confidenza al 100%Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org Confidenza al 100%Help Scout is a customer service platform including email, a knowledge base tool and live chat.
www.helpscout.com Confidenza al 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confidenza al 100%Analisi di VirusTotal
Prove archiviate
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of mtoken-im.cv · checked Aug 1, 2026
Dati e relazioni esterne
PD-20260801-082241 Recipient: abuse@v-sys.org Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo