mail[.]phantomwallet-s[.]us
“Phantom Wallet - Download Your Phantom Wallet - Phantom”
mail.phantomwallet-s.us — Conteúdo indisponível (HTTP 502). Representação da marca: Ethereum; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 14/95 (ADMINUSLabs, BitDefender, CRDF, CyRadar, ESET); URLQuery 4 alerts; PhishDestroy score 95/100. Registrador: NameSilo.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, mail.phantomwallet-s.us, was registered on February 21 2026 through NameSilo, LLC and is hosted on the IP address 162.241.27.225 belonging to AS46606 Unified Layer in the United States. The authoritative nameservers are sns015.bigrock.com and sns016.bigrock.com. No TLS certificate is presented, indicating that the site does not support HTTPS. The HTTP service is currently offline, and the page title that was observed before takedown reads “Phantom Wallet - Download Your Phantom Wallet - Phantom,” which aligns with the reported crypto‑scam classification.
The domain is explicitly listed as impersonating the Ethereum brand. Infrastructure reputation is extremely poor: Gridinsoft assigns a trust score of 0 out of 100, and the domain appears on three independent security blocklists, including PhishDestroy, MetaMask, and SEAL. VirusTotal analysis shows that 14 of 95 scanning engines flagged the domain as malicious, corroborating the blocklist findings. The combination of a brand‑impersonation claim, a fabricated wallet download page, a lack of encryption, and multiple independent detections suggests a high‑confidence crypto‑phishing operation.
Because the site is presently taken offline, direct payload analysis is not possible, and the exact content served cannot be verified. Defenders should continue to block the domain and its resolved IP at network perimeters, add the domain to internal URL filtering policies, and monitor for any resurgence or related domains using the same nameservers or hosting ASN. Ongoing threat‑intel feeds should be consulted for new indicators, and any user reports of unsolicited Ethereum‑related wallet download links should be escalated for investigation.
Inteligência de segurança de rede Registrar context
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência forense
Análise do VirusTotal
Evidências e relatórios externos
PD-20260207-6A5419 Recipient: abuse@bluehost.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo