phanton-wallet[.]fi-v2[.]to
“phanton-wallet.fi-v2.to”
phanton-wallet.fi-v2.to — Контент недоступний. Уособлення бренду: Phantom; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 20/95 (ADMINUSLabs, ChainPatrol, Criminal IP, alphaMountain.ai, BitDefender); URLScan malicious verdict; Spamhaus DBL_PHISH; 1 external blocklist match (ScamSniffer); PhishDestroy score 95/100. Реєстратор: Government of Kingdom ….
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain phanton-wallet.fi-v2.to is identified as a high-risk brand impersonation threat specifically targeting Phantom, a widely used cryptocurrency wallet service. Analysis indicates this infrastructure was designed to deceive users into believing they are interacting with the legitimate Phantom platform, likely for the purpose of credential harvesting or crypto asset theft. The domain is currently offline, though its prior operational status poses residual risk to users who may have encountered it during its active period. Infrastructure analysis reveals multiple high-confidence indicators of malicious activity. The domain was flagged by 20 of 95 security vendors on VirusTotal, demonstrating broad consensus among detection engines. It was registered on November 17, 2025, through the Government of the Kingdom of Tonga, an uncommon registrar choice that often correlates with fraudulent domains. The domain resolves to an IPv6 address (2606:4700:3033::6815:37b9) hosted on AS13335, a network frequently utilized for content delivery but also exploited for malicious purposes. Additionally, the domain appears on three security blocklists, including PhishDestroy, ScamSniffer, and PhishingDB, and lacks a valid SSL certificate, further undermining its legitimacy. Given the domain's current offline status, immediate interaction risks are mitigated; however, users who accessed this domain prior to its takedown should assume potential compromise. It is recommended to revoke any wallet permissions granted during the suspected exposure period, monitor accounts for unauthorized transactions, and verify all subsequent interactions with the official Phantom platform exclusively. Organizations should update internal blocklists to include this domain and its associated indicators, while users are advised to enable multi-factor authentication and employ browser-based security extensions to detect similar threats in real time.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога