en-phantomwallet[.]com
Проверка домена en-phantomwallet.com на фишинг и безопасность
“Phantom Wallet - Download Best Crypto Wallet - Phantom Wallet”
en-phantomwallet.com — Контент недоступен (HTTP 502). Олицетворение бренда: Phantom; Тип мошенничества: Wallet/seed Phishing. Сводка доказательств: VirusTotal 15/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); URLQuery 100 det.; PhishDestroy score 95/100. Регистратор: ENOM.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain en-phantomwallet.com was registered on September 04, 2025 through ENOM, INC. and is currently listed as offline. DNS resolution points to the IPv4 address 142.11.248.171, which belongs to Hostwinds LLC (AS54290) and is geolocated in the United States. Authoritative name servers dalbs125.hostwindsdns.com and dalbs126.hostwindsdns.com confirm the hosting relationship with Hostwinds.
The site presented the page title "Phantom Wallet - Download Best Crypto Wallet - Phantom Wallet," explicitly targeting the Phantom brand and aligning with the reported scam type of wallet/seed phishing. No TLS certificate was observed, indicating the absence of HTTPS protection at the time of analysis. Reputation data shows a Gridinsoft trust score of 0 out of 100, and the domain appears on a single security blocklist where it has been blocked by PhishDestroy. VirusTotal scans recorded 15 detections out of 95 security vendors, reinforcing the malicious classification.
While the domain is presently taken offline, the infrastructure footprints—including the dedicated Hostwinds hosting, lack of SSL, and low trust score—suggest a deliberate, brand‑impersonation campaign. Defenders should continue to block the IP 142.11.248.171 at perimeter devices, update URL filtering rules to include en-phantomwallet.com, and monitor for any resurgence of related domains using the same name server pair or hosting ASN. Additional investigation should focus on any residual HTTP artifacts and potential credential‑harvesting endpoints that may have been active before takedown.
Сигналы безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криминалистическая аналитика
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание