finance-phantomapp[.]ca
“Trade confidently with the Finance Phantom crypto platform today”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
This domain is classified as a high-risk crypto brand impersonation site designed to deceive users into engaging with fraudulent financial platforms. The infrastructure mimics Phantom, a legitimate cryptocurrency wallet provider, with the intent to facilitate unauthorized transactions, credential theft, or direct crypto asset drainage. The domain exhibits multiple technical indicators consistent with malicious activity, including recent registration, association with bulletproof hosting providers, and active security vendor detections. Analysis indicates the domain finance-phantomapp.ca was registered on October 13, 2025, through Go Get Canada Domain Registrar Ltd. It resolves to IP address 104.21.19.148, hosted on AS13335 (Cloudflare, Inc.), a network frequently leveraged by threat actors to obfuscate origin infrastructure. The site is flagged by 17 out of 95 security vendors on VirusTotal, with Google Safe Browsing explicitly categorizing it as phishing. The SSL certificate is issued by Google Trust Services (WE1), a common practice among malicious domains to appear legitimate. The domain appears on one security blocklist and is actively blocked by PhishDestroy. The page title, 'Trade confidently with the Finance Phantom crypto platform today,' directly impersonates Phantom’s branding and messaging. Mitigation requires immediate action from security teams and end users. Network-level blocking of the domain and its resolving IP (104.21.19.148) should be enforced across firewalls, DNS filters, and endpoint protection systems. Users who may have interacted with the site should revoke any connected wallet permissions, rotate credentials for associated accounts, and monitor transaction histories for unauthorized activity. Cryptocurrency exchanges and wallet providers should flag the domain in their fraud detection systems and alert users attempting to access it. Due to the high-risk nature of crypto drainer schemes, incident response teams should treat any interaction with this domain as a potential compromise requiring forensic analysis of affected devices.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Status do domínio
Acessível → Inacessível
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
-
Status do domínio
Inacessível → Acessível
Tecnologias
1 tecnologia identificada com alta confiança
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo