ask-phantm-wlts[.]pages[.]dev
“GitHub - MRKrog/phantom-wallet: Replica Phantom Wallet”
Збережене спостереження
Зафіксована відмінність заголовків
Зведення доказів
PhishDestroy identifies an active phishing campaign hosted at ask-phantm-wlts.pages.dev, a fraudulent domain masquerading as a cryptocurrency wallet security portal. This site is designed to deceive users into surrendering sensitive credentials or downloading malicious payloads under the guise of wallet security updates. The threat actor leverages Cloudflare Pages to host the phishing content, which currently resolves to IP 172.66.47.186 via Cloudflare’s infrastructure. The SSL certificate, issued by Google Trust Services, adds a veneer of legitimacy, increasing the risk of successful deception. With no detections on VirusTotal as of the latest scan (1/95), this campaign remains under the radar, making it a stealthy and evolving threat to cryptocurrency users. This domain was flagged for generic phishing activities and is currently under investigation. Key technical indicators include registration through Cloudflare, Inc., a resolution to IP 172.66.47.186, and the use of a Google Trust Services SSL certificate to mimic legitimate security protocols. The absence of detections on VirusTotal (1/95) highlights the evasive nature of this campaign, as traditional security tools have yet to flag the domain. Given its active status and lack of detection, the risk of exposure to unsuspecting users remains high, particularly for those unfamiliar with verifying domain authenticity or security certificate issuers. Users who have encountered or visited ask-phantm-wlts.pages.dev should immediately cease any interaction with the site and avoid entering sensitive information, including wallet credentials, private keys, or personal data. If credentials or sensitive information were entered, users must revoke access to their cryptocurrency wallets or financial accounts immediately, monitor for unauthorized transactions, and scan their devices for malware using reputable security software. Report the domain to your wallet provider or relevant cybersecurity authorities to aid in its takedown. Always verify security alerts or wallet notifications by accessing official channels directly through verified URLs or applications, and never rely on unsolicited links or domains for critical security updates.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
8 зовнішніх джерел під наглядом Збігів немає
Технології
Виявлено 3 технології з високою впевненістю
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of ask-phantm-wlts.pages.dev · checked May 4, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога