p-hantomwalletextensionn[.]pages[.]dev
“Phantom Wallet | Extension Download | Official Site”
p-hantomwalletextensionn.pages.dev — İçerik kullanılamıyor. Marka kimliğine bürünme: Phantom; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 2/94 (ADMINUSLabs, Fortinet); PhishDestroy score 61/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
PhishDestroy identifies p-hantomwalletextensionn.pages.dev as a brand impersonation domain targeting Phantom users. The domain uses a multi-character typo-squatting pattern (p-hantom vs. phantom) to mimic Phantom's official extension branding. This site is likely a cryptocurrency wallet drainer kit designed to deceive users into connecting their wallets and approving malicious token approvals or transfers. The domain leverages Cloudflare Pages for hosting, which provides SSL termination via Google Trust Services certificates, adding a veneer of legitimacy to the fraudulent site.
This domain resolves to IP 188.114.97.3 and remains undetected by VirusTotal with a score of 2/95 detections as of last assessment. It is registered through Cloudflare, Inc., and the exact creation date is not reflected in available data. Google Safe Browsing (GSB) has not yet flagged the domain, and no current blocklist entries were detected. The absence of detections suggests a newly deployed campaign that has not yet triggered automated security responses.
The domain is currently active and under investigation by threat intelligence teams. Users are advised not to interact with p-hantomwalletextensionn.pages.dev or any similarly named Phantom-related domains. Blocking the domain at the network level and reporting it to Phantom and relevant security vendors is recommended. Although current risk is elevated due to low detection, the campaign may expand or evolve rapidly. Remaining risk includes potential wallet compromise and fund theft, particularly targeting users searching for Phantom wallet extensions. Immediate defensive actions are strongly advised.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Adli İstihbarat
Teknolojiler · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of p-hantomwalletextensionn.pages.dev · checked Mar 25, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin