idigitalonline[.]com
“im钱包下载-imToken钱包-imToken安装下载地址”
idigitalonline.com — Контент недоступен (HTTP 502). Олицетворение бренда: ImToken; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 17/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLQuery 100 det.; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Регистратор: Gname.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain idigitalonline.com has been identified as a brand impersonation threat specifically targeting imToken, a popular cryptocurrency wallet. This domain is now offline, but during its active period it attempted to deceive users by mimicking the legitimate imToken platform. The page title, 'im钱包下载-imToken钱包-imToken安装下载地址', clearly indicates an intent to trick users into downloading a fake wallet application.
Security analysis reveals that the domain was created on December 20, 2024, through registrar Gname.com Pte. Ltd., and resolved to IP address 188.114.97.3. Its SSL certificate was issued by Let's Encrypt (R12), which is common for both legitimate and malicious sites. VirusTotal flagged the domain as malicious by 17 out of 95 security vendors, and it appears on one security blocklist. These indicators collectively suggest a high likelihood of fraudulent activity.
Given that the domain is now offline, the immediate risk is mitigated, but users should remain vigilant. PhishDestroy recommends always verifying the authenticity of any website before entering sensitive information, especially when dealing with cryptocurrency platforms. If you encounter similar domains, report them immediately and rely on official sources for software downloads.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 7 identified
Popular CSS framework for responsive, mobile-first web development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Touch-enabled jQuery plugin for responsive carousel sliders.
Plugin to detect and restore deprecated jQuery features.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание