ask-phantm-wlts[.]pages[.]dev
“GitHub - MRKrog/phantom-wallet: Replica Phantom Wallet”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
PhishDestroy identifies an active phishing campaign hosted at ask-phantm-wlts.pages.dev, a fraudulent domain masquerading as a cryptocurrency wallet security portal. This site is designed to deceive users into surrendering sensitive credentials or downloading malicious payloads under the guise of wallet security updates. The threat actor leverages Cloudflare Pages to host the phishing content, which currently resolves to IP 172.66.47.186 via Cloudflare’s infrastructure. The SSL certificate, issued by Google Trust Services, adds a veneer of legitimacy, increasing the risk of successful deception. With no detections on VirusTotal as of the latest scan (1/95), this campaign remains under the radar, making it a stealthy and evolving threat to cryptocurrency users. This domain was flagged for generic phishing activities and is currently under investigation. Key technical indicators include registration through Cloudflare, Inc., a resolution to IP 172.66.47.186, and the use of a Google Trust Services SSL certificate to mimic legitimate security protocols. The absence of detections on VirusTotal (1/95) highlights the evasive nature of this campaign, as traditional security tools have yet to flag the domain. Given its active status and lack of detection, the risk of exposure to unsuspecting users remains high, particularly for those unfamiliar with verifying domain authenticity or security certificate issuers. Users who have encountered or visited ask-phantm-wlts.pages.dev should immediately cease any interaction with the site and avoid entering sensitive information, including wallet credentials, private keys, or personal data. If credentials or sensitive information were entered, users must revoke access to their cryptocurrency wallets or financial accounts immediately, monitor for unauthorized transactions, and scan their devices for malware using reputable security software. Report the domain to your wallet provider or relevant cybersecurity authorities to aid in its takedown. Always verify security alerts or wallet notifications by accessing official channels directly through verified URLs or applications, and never rely on unsolicited links or domains for critical security updates.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Teknolojiler
3 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of ask-phantm-wlts.pages.dev · checked May 4, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin