atomicwallet[.]trade
“Atomic Wallet : Buy, Stake and Exchange in One Crypto Wallet”
atomicwallet.trade — コンテンツが利用できません (HTTP 502). ブランドの偽装: Atomic Wallet; 詐欺タイプ: Crypto Scam. 証拠の概要: VirusTotal 2/93 (SOCRadar, Webroot); PhishDestroy score 56/100.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
The domain www.atomicwallet.trade was registered on February 25, 2026 and was observed hosting a page whose title reads “Atomic Wallet : Buy, Stake and Exchange in One Crypto Wallet”. The page title explicitly references the legitimate brand Atomic Wallet, indicating a brand‑impersonation campaign aimed at crypto users. Technical fingerprinting shows the site was served over Nginx with a PHP backend and employed HTTP Strict Transport Security (HSTS), suggesting an attempt to appear legitimate. The TLS certificate was issued by the R3 intermediate authority, a common Let’s Encrypt chain, and the site resolved to the IP address 172.96.187.218, which belongs to AS32475 (Internap Holding LLC) located in the United States.
Two of ninety‑three VirusTotal scanners flagged the domain, and the domain appears on one external security blocklist. The phishing‑defense platform PhishDestroy listed the domain as blocked, and the current operational status is offline, indicating that the site has been taken down or otherwise removed from public access. No further content analysis, such as login form capture or malware payload, is publicly available.
Given the confirmed brand impersonation and the presence of a valid SSL certificate, threat actors likely intended to harvest cryptocurrency credentials or lure victims into fraudulent transactions. Defenders should add www.atomicwallet.trade to URL filtering and DNS blocklists, monitor the hosting IP 172.96.187.218 for related activity, and review any recent authentication attempts against legitimate Atomic Wallet services for signs of credential reuse. Continuous observation of the associated IP range and periodic re‑scanning of the domain are recommended to detect any re‑activation attempts.
脅威対応 Pipeline
公開ブロックリスト登録状況
使用技術 · 3 identified
Server-side scripting language designed for web development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotalによる分析
アーカイブ済み証拠
証拠および外部報告書
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください