tolami[.]site
“OppiWallet - Secure Crypto Wallet & Payment Platform”
tolami.site — Conteúdo indisponível (HTTP 502). Representação da marca: Apple; Tipo de golpe: Tech Support Scam. Resumo das evidências: VirusTotal 4/93 (Bfore.Ai PreCrime, CRDF, Gridinsoft, MalwareURL); PhishDestroy score 71/100. Registrador: NameCheap.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of the domain tolami.site, observed on July 24, 2026, indicates an elevated‑risk brand‑impersonation operation targeting Apple. The domain was registered on May 25, 2025 through NameCheap, Inc. and resolves to the IPv6 address 2a06:98c1:3120::3, which is hosted by Cloudflare (AS13335) in the United States. The site is currently offline, and its status is recorded as taken offline in the intelligence feed. The page title returned by the server reads “OppiWallet - Secure Crypto Wallet & Payment Platform,” suggesting a cryptocurrency‑related lure, while the listed scam type is a Tech Support Scam, implying that victims may be prompted to grant remote access or install malicious utilities.
The domain appears on a single security blocklist and is actively blocked by PhishDestroy, providing a concrete mitigation point for network defenders. VirusTotal scans show that four of ninety‑three security vendors flagged the domain, reinforcing the suspicion of malicious intent despite a limited detection footprint. The SSL certificate is identified only as “WE1,” offering no additional validation of legitimacy. Gridinsoft assigns a trust score of 0 / 100, effectively marking the site as untrusted.
No further evidence about the page’s content, phishing kit, or credential‑capture mechanisms is available. Given the combination of brand‑impersonation labeling, the Apple target, the tech‑support scam classification, and the presence on blocklists, defenders should continue to block tolami.site at the DNS and firewall layers, monitor the associated IP address for reuse, and include the domain in threat‑intel feeds. Continuous observation of any re‑registration attempts or similar naming patterns is recommended, as the infrastructure—particularly the Cloudflare‑served IPv6 address—could be repurposed for future campaigns.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo