imtoken-upay[.]com
“imToken official website|Ethereum and Bitcoin blockchain wallet”
Resumo das evidências
Analysis of imtoken-upay.com, observed as an offline malicious site, confirms it is being used for wallet/seed phishing targeting users of the Arbitrum ecosystem. The domain was registered on 21 February 2026 through Dominet (HK) Limited and is serviced by four authoritative name servers (ns1.domainnamedns.com, ns2.domainnamedns.com, ns3.domainnamedns.com, ns4.domainname). No TLS certificate is presented, and HTTP requests return no valid response, consistent with the reported offline status. DNS resolution points to IP 20.247.100.105, which is hosted in Hong Kong under ASN 132839 (POWER LINE DATACENTER).
The hosting provider and geographic location are consistent with other infrastructure observed in recent crypto‑phishing campaigns. Reputation data show a Gridinsoft trust score of 0 / 100 and the domain appears on a single security blocklist. PhishDestroy has already blocked the host, and 16 of 95 security vendors on VirusTotal flag the domain as malicious, reinforcing the suspicion of illicit activity.
The page title returned by the site, “imToken official website|Ethereum and Bitcoin blockchain wallet”, is unrelated to the claimed target brand Arbitrum, indicating a deliberate brand‑impersonation tactic to lure victims. Given the convergence of registrar information, low trust score, blocklist inclusion, and multi‑vendor detections, defenders should immediately add imtoken-upay.com to network and endpoint block lists, monitor DNS queries for the four listed name servers, and enforce email and web filtering rules that flag any references to the brand Arbitrum originating from this domain. Continuous re‑evaluation is advised in case the site returns online, as the current offline state does not preclude future activation.
Instantâneo das evidências enviadas
- Enviado
- Registros do livro-razão
- 1
- ID do caso
PD-20260203-4F6E35- Título da página capturada
- imToken official website|Ethereum and Bitcoin blockchain wallet
- Artefato PDF
- Evidência em PDF
Base jurídica
Texto completo da evidência
Acceptable Use Policy (AUP): The domain imtoken-upay.com is engaged in phishing activities, which directly contravenes the AUP by facilitating fraud and deception against unsuspecting users.
Terms of Service (TOS): The registrar reserves the right to suspend or terminate services for violations. The ongoing operation of this domain constitutes a clear violation of these terms, warranting immediate action.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): Prohibits unauthorized access to computers and networks, which is applicable as phishing schemes typically involve deceptive practices to gain sensitive information.
Wire Fraud Statute (18 U.S.C. § 1343): Criminalizes schemes to defraud individuals or entities through electronic communications, which is relevant given the fraudulent nature of phishing.
CAN-SPAM Act (15 U.S.C. § 7701): Regulates commercial email and prohibits misleading headers and deceptive subject lines, both of which are often employed in phishing attacks.
Regulatory Note: Failure to take appropriate action against this domain may expose your organization to legal liabilities and regulatory scrutiny. Immediate compliance with your AUP and TOS is essential to mitigate potential risks.
Data Coverage
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | imtokens.co |
malicious | Sinkholed |
| Cloudflare DNS | imtokens.co |
malicious | Sinkholed |
| Quad9 DNS | imtokens.co |
malicious | Sinkholed |
| DNS4EU | imtokens.co |
malicious | Sinkholed |
| OpenDNS | m.imtoken-upay.com |
phishing | Phishing Block |
| DNS4EU | m.imtoken-upay.com |
malicious | Sinkholed |
| OpenDNS | imtoken-upay.com |
phishing | Phishing Block |
| DNS4EU | imtoken-upay.com |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo