MALICIOUS — HIGH
atomic-wallet[.]help
The domain atomic-wallet.help was registered on February 21, 2026 through URL Solutions, Inc.
- VirusTotal
- 5/95
- Blocklists
- No stored match
- Disponibilidade
- Conteúdo indisponível · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
atomic-wallet.help — Conteúdo indisponível (HTTP 502). Representação da marca: Atomic Wallet; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 5/95 (alphaMountain.ai, Chong Lua Dao, Gridinsoft, Seclookup, SOCRadar); PhishDestroy score 65/100. Registrador: URL Solutions.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Evidence Analysis
The domain atomic-wallet.help was registered on February 21, 2026 through URL Solutions, Inc. and is hosted on nameservers ns1.fozzy.com and ns2.fozzy.com. DNS resolution points to the loopback address 127.0.0.1, indicating that the site is no longer serving content and is currently offline. No SSL certificate is present, meaning any attempted HTTPS connection would fail or be forced to HTTP, a typical characteristic of low‑effort fraudulent infrastructure.
Malware and reputation services have flagged the domain: VirusTotal reports five of ninety‑five scanners labeling it malicious, and Gridinsoft assigns a trust score of zero out of one hundred. The domain appears on three public blocklists and is explicitly blocked by PhishDestroy, MetaMask, and SEAL, reinforcing the view that it is being used for a crypto‑related scam targeting users of the Atomic Wallet brand. The only confirmed indicator of the scam type is the label "Crypto Scam" in the intelligence feed; no page title, content snapshot, or additional technical artifacts have been released, so the exact phishing page design and credential‑harvesting mechanisms remain unknown.
Defenders should continue to deny network traffic to atomic-wallet.help, add the domain to outbound filtering rules, and monitor for any re‑registration or resurrection of the domain under new IP addresses. Security teams should also update endpoint and email protection signatures to include the observed VirusTotal detections and ensure that any references to the Atomic Wallet brand are cross‑checked against this malicious indicator. Continuous threat‑intel feeds should be consulted for any future activity linked to the same registrar or nameserver pair, as adversaries often reuse these components in subsequent campaigns.
Cobertura dos dados12 recorded checks
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Evidências e relatórios externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.