phantom-wallet-getting[.]created[.]app
“How to get started with Phantom – Phantom”
Сохранённое наблюдение
Зафиксированное различие заголовков
Сводка доказательств
This domain, phantom-wallet-getting.created.app, was registered through Tucows Domains Inc. on July 12, 2023 and is currently hosted on Amazon’s AS16509 network in the United States, resolving to IP address 216.150.16.193. The infrastructure is served via Vercel with DNS entries ns1.vercel-dns.com and ns2.vercel-dns.com, and the site is delivered through Google Cloud CDN, with HSTS enforced. A Let’s Encrypt certificate (R13) is present, indicating HTTPS availability at the time of observation. The HTTP response returned a 404 status, and the page title retrieved from the site reads “How to get started with Phantom – Phantom,” which directly aligns with the brand impersonation claim targeting the Phantom cryptocurrency wallet. The domain is classified as a crypto‑scam and was identified as impersonating the legitimate Phantom brand.
Security intelligence shows that the domain appears on a single blocklist and has been blocked by the PhishDestroy sinkhole service. VirusTotal analysis recorded 13 positive detections out of 93 scanned vendors, providing additional corroboration of malicious intent. The presence of LaunchDarkly and other modern web‑app frameworks suggests the operators employed a typical SaaS‑based hosting stack rather than a dedicated malicious infrastructure. No further content was captured, and the site is reported as offline at the time of this investigation.
Uncertainty remains regarding the specific phishing page content and any credential‑harvesting mechanisms, as the only observable artifact is the page title and HTTP 404 response. Defensive teams should add the domain and its associated IP address to blocklists, monitor for DNS resolutions to the Vercel nameservers, and enforce URL filtering for any URLs containing the “phantom‑wallet‑getting” pattern. Continuous re‑verification of the block status is advised, as the infrastructure could be re‑activated under a different sub‑domain.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Registration: created.app
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain created.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии
Выявлено 5 технологий с высокой уверенностью
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание