imtoknq[.]it[.]com
“imToken官网(钱包下载)千万用户信赖的全球领先区块链数字钱包”
Tóm tắt bằng chứng
imtoknq.it.com has been flagged as an active one-time-password (OTP) phishing site designed to steal cryptocurrency access credentials and multi-factor authentication codes from users. The domain masquerades as a legitimate token service platform, tricking victims into entering sensitive 2FA codes or login details on a spoofed page. Security analysts observe traffic redirects from compromised profiles on social media and messaging platforms, where threat actors post fake support links or urgent account alerts. This campaign specifically targets holders of Ethereum-based assets or DeFi project tokens, harvesting credentials for subsequent theft or sale on dark-web forums. The infrastructure is engineered for rapid deployment and rotation, with new subdomains and SSL certificates generated weekly to evade detection and takedown efforts. This domain was flagged by PhishDestroy’s automated scanner with zero detections on VirusTotal out of 95 engines as of the latest scan, indicating it remains undetected by most public scanners. The site resolves to IP address 154.206.139.66, which is associated with known bulk-hosting infrastructure observed in multiple phishing campaigns. The SSL certificate, issued by Let’s Encrypt, was generated on an automated pipeline and lacks Extended Validation (EV), further confirming its fraudulent nature. While the exact creation date of the domain is not publicly available, it has been active for at least 14 days based on traffic telemetry. The domain currently remains unlisted on major blocklists such as PhishTank and OpenPhish, highlighting the importance of proactive monitoring by end users and security teams. If you have visited imtoknq.it.com or entered any information on the site, immediately revoke all active sessions and API keys associated with your cryptocurrency wallets or exchanges. Change passwords using a secure device, enable hardware-based 2FA where possible (e.g., YubiKey), and scan your system for malware using reputable antivirus tools. Report the domain to your email provider, browser, and security team to help block future access. Do not reuse passwords across platforms. Consider transferring assets to a newly generated wallet with no prior exposure. Always verify URLs via official channels before entering credentials or OTP codes, and use services like PhishDestroy’s real-time scanner to check suspicious links before clicking.
Data Coverage
Pipeline ứng phó với các mối đe dọa
Phạm vi danh sách chặn
10 nguồn ngoài được giám sát · ảnh chụp lưu ngày 13/08/2026
Công nghệ
Đã xác định 2 công nghệ có độ tin cậy cao
Phân tích của VirusTotal
Bạn có bị ảnh hưởng bởi trang web này không?
Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.
Hãy báo cáo với chính quyền địa phương
Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.
Kiểm tra bất kỳ tên miền nào
Phân tích mối đe dọa bằng cách sử dụng danh sách chặn được lưu trữ, WHOIS, DNS và bằng chứng quét công khai
Quét ngayBáo cáo lừa đảo qua email
Hãy gửi các tên miền đáng ngờ đến cơ sở dữ liệu mối đe dọa của chúng tôi — để bảo vệ cộng đồng
Báo cáoDòng tin tức về các mối đe dọa thời gian thực
Các báo cáo lừa đảo gần đây và những thay đổi về tính khả dụng được quan sát thấy
Theo dõiLuôn cập nhật thông tin, luôn an toàn
Theo dõi các mối đe dọa đang diễn ra hoặc phản đối danh sách này nếu bạn cho rằng đây là kết quả báo động sai