phantomwalletdownload[.]blogspot[.]com[.]mt
“Phantom Wallet Download”
phantomwalletdownload.blogspot.com.mt — Não verificado. Representação da marca: Phantom; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 10/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, ESET, Fortinet); PhishDestroy score 80/100. Registrador: GOOGLE (ASN: 15169).
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, phantomwalletdownload.blogspot.com.mt, is actively impersonating Phantom, a cryptocurrency wallet service, as indicated by its page title 'Phantom Wallet Download' and confirmed brand target data. Registered under AS15169 (Google LLC), the domain resolves to IP 142.251.40.225, located in the United States, and is hosted on Blogger infrastructure. Analysis reveals the use of technologies including Java, Python, OpenGSE, and HTTP/3, which are consistent with legitimate web services but are being exploited here for malicious purposes. The domain currently returns an HTTP 302 redirect status, suggesting it may be dynamically routing visitors to other malicious endpoints or serving deceptive content. It appears on one security blocklist and is flagged by 8 out of 95 security vendors on VirusTotal, indicating a high likelihood of malicious activity. The scam type is classified as cryptocurrency-related, aligning with the impersonation of a well-known wallet provider to likely harvest credentials or distribute malware. Infrastructure analysis shows the domain uses an SSL certificate issued by Google Trust Services, which does not inherently validate the legitimacy of the site but ensures encrypted connections. The exact content served by the domain remains unconfirmed, as no direct analysis of the page has been conducted beyond its title and classification. Defenders should treat this domain as high-risk and prioritize blocking or monitoring traffic to it, particularly in environments where cryptocurrency-related services are accessed. Given the domain's active status and association with a trusted hosting provider, organizations should investigate any historical or ongoing connections to 142.251.40.225 or the domain itself. The use of Blogger as a platform for this scam underscores the need for heightened scrutiny of subdomains and third-party hosted content, even when the parent domain is reputable.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 5 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo