imtoken-world[.]com
Перевірка домену imtoken-world.com на фішинг і безпеку
“imToken official website|Ethereum and Bitcoin blockchain wallet”
imtoken-world.com — Контент недоступний (HTTP 502). Уособлення бренду: Arbitrum; Тип шахрайства: Wallet/seed Phishing. Зведення доказів: VirusTotal 11/95 (alphaMountain.ai, CRDF, Emsisoft, Fortinet, G-Data); URLQuery 8 alerts; PhishDestroy score 93/100. Реєстратор: Dominet (HK).
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain imtoken-world.com was registered on February 21, 2026 through Dominet (HK) Limited and is currently taken offline. Its authoritative name servers are ns1.domainnamedns.com, ns2.domainnamedns.com, ns3.domainnamedns.com and ns4.domainname. No TLS certificate is presented, indicating that the site was served over plain HTTP when it was reachable. DNS resolution points to 20.247.100.105, an address announced by AS132839 POWER LINE DATACENTER in Hong Kong. The hosting infrastructure therefore resides in the same jurisdiction as the registrar.
A Gridinsoft trust score of 0 out of 100 marks the site as highly untrusted. The page title observed during the brief availability period was "imToken official website|Ethereum and Bitcoin blockchain wallet," which the operators used while targeting the arbitrum brand. The scam type is classified as wallet/seed phishing, suggesting attempts to harvest private keys or recovery phrases from victims. Detection by security vendors is strong: 11 of 95 VirusTotal scanners flagged the domain, and it appears on one public blocklist.
PhishDestroy has already added the domain to its blocklist, confirming that the site was considered malicious. The combination of a brand‑impersonating page title, lack of encryption, low trust score, and multiple vendor detections indicates a coordinated credential‑harvesting campaign rather than a benign misconfiguration. Defenders should continue to block the domain and its associated IP address at perimeter filters, monitor for new domains using the same name‑server pattern or registrar, and enforce strict verification of wallet‑related URLs, especially those claiming association with arbitrum or imToken. Incident response teams should also look for any user reports of seed phrase requests that match the timeframe of this domain’s activity, and consider outreach to affected users to remind them of official wallet endpoints.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | m.imtoken-world.com |
phishing | Phishing Block |
| DNS4EU | m.imtoken-world.com |
malicious | Sinkholed |
| DigiCert UltraDNS | imtokens.co |
malicious | Sinkholed |
| Cloudflare DNS | imtokens.co |
malicious | Sinkholed |
| DNS4EU | imtokens.co |
malicious | Sinkholed |
| Quad9 DNS | imtokens.co |
malicious | Sinkholed |
| OpenDNS | imtoken-world.com |
phishing | Phishing Block |
| DNS4EU | imtoken-world.com |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
PD-20260203-B3AAD7 Recipient: domainabuse@service.aliyun.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога