imtoknk[.]com[.]cn
“imToken钱包 - 安全的加密货币钱包下载 | iOS/Android官方版”
imtoknk.com.cn — Контент недоступний. Зведення доказів: VirusTotal 19/91 (ADMINUSLabs, alphaMountain.ai, Cluster25, CRDF, ESET); URLQuery 2 alerts; PhishDestroy score 95/100. Реєстратор: Dynadot.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, imtoknk.com.cn, is identified as an active phishing infrastructure specifically designed to impersonate the imToken cryptocurrency wallet. The threat type is classified as generic phishing with a high-risk designation, targeting users seeking legitimate iOS or Android wallet applications. Analysis confirms the domain is currently operational and mirrors the branding of the authentic imToken platform, a widely used digital asset management service. Infrastructure analysis reveals the domain was registered on May 24, 2026, through Dynadot Inc, a registrar commonly associated with both legitimate and malicious registrations. It resolves to the IP address 154.206.138.207, which has been linked to other suspicious activities in recent threat intelligence reports. The domain appears on one security blocklist and is flagged by 19 of 95 security vendors on VirusTotal, indicating a moderate to high level of detection. The SSL certificate is issued by Let's Encrypt (R13), a common certificate authority used by both benign and malicious sites to establish encrypted connections. The page title, 'imToken钱包 - 安全的加密货币钱包下载 | iOS/Android官方版,' directly mimics the official imToken branding, increasing the likelihood of user deception. Current status confirms the domain remains active and continues to host phishing content. Users and organizations are advised to block the domain and its associated IP address (154.206.138.207) at the network level. Cryptocurrency wallet users should verify the authenticity of download sources by accessing only the official imToken website or verified app store listings. Security teams are recommended to monitor for additional domains registered through the same registrar or resolving to the same IP range, as this may indicate a broader campaign. Immediate reporting to relevant security platforms and certificate authorities is advised to mitigate further risk.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | imtoknk.com.cn |
malicious | Sinkholed |
| OpenDNS | imtoknk.com.cn |
phishing | Phishing Block |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
PD-20260524-ADB403 Recipient: bandalgopi709@gmail.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога