MALICIOUS — CRITICAL
phantomvxcx[.]it[.]com
5 of 91 security engines flagged the domain; 1 public blocklist listed it (ScamSniffer); the latest stored check returned HTTP 502.
- VirusTotal
- 5/91
- Blocklists
- 1 · ScamSniffer
- sẵn có
- Nội dung không có sẵn · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
phantomvxcx.it.com — Nội dung không có sẵn (HTTP 502). Mạo danh thương hiệu: Phantom; Loại lừa đảo: Crypto Scam. Tóm tắt bằng chứng: VirusTotal 5/91 (ChainPatrol, alphaMountain.ai, BitDefender, G-Data, Gridinsoft); URLQuery 100 det.; URLScan malicious verdict; 1 external blocklist match (ScamSniffer); PhishDestroy score 95/100. Nhà đăng ký: Intis Telecom.
Phân tích chi tiết của PhishDestroy AI bên dưới được giữ bằng tiếng Anh để bảo toàn hồ sơ pháp chứng gốc.
Evidence Digest
phantomvxcx.it.com is classified critical with an evidence score of 95/100. 5 of 91 security engines flagged the domain; 1 public blocklist listed it (ScamSniffer). Registered 23 Oct 1992 via Intis Telecom LTD, hosted on 172.67.206.147 (CLOUDFLARENET, US, US). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture. 1 outgoing abuse report is recorded, most recently on 6 Jan 2026.
Stored generated summary (templated)mistral · 23/07/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
Analysis of the domain phantomvxcx.it.com indicates it was involved in a crypto scam operation impersonating Phantom, a known cryptocurrency wallet brand. The domain, registered through Intis Telecom LTD on October 23, 1992, exhibits characteristics consistent with brand impersonation campaigns. Infrastructure analysis reveals the domain resolved to the IP address 172.67.206.147, hosted under AS13335 (Cloudflare, Inc.) in the United States. Nameserver records include margo.ns.cloudflare.com alongside ns1.it.com, ns2.it.com, and ns3.it.com, suggesting a hybrid DNS configuration potentially leveraged to evade detection or takedown efforts.
Security vendor detections on VirusTotal flagged the domain as malicious, with 8 out of 93 vendors identifying it as a threat. The domain appears on two security blocklists, including PhishDestroy and ScamSniffer, further corroborating its association with fraudulent activity. No SSL certificate was present at the time of assessment, which is atypical for legitimate financial or crypto-related services and may have served as an additional red flag for security tools. The page title, recorded as phantomvxcx.it.com/#/, does not provide additional context beyond the domain name itself, and no further content analysis is available.
The domain has since been taken offline, though its historical registration date—October 23, 1992—is anomalous for a campaign of this nature, potentially indicating domain repurposing or registry inaccuracies. Defenders are advised to monitor for re-registration or similar domains under the same registrar or hosting provider. Given the elevated risk level, organizations should ensure blocklist updates include this domain and consider proactive detection for related infrastructure patterns, such as Cloudflare-hosted domains with crypto-related keywords or Phantom brand impersonation.
Phạm vi dữ liệu12 recorded checks
Pipeline ứng phó với các mối đe dọa
Trạng thái trong danh sách chặn công khai
Phân tích của VirusTotal
Bằng chứng và các báo cáo bên ngoàiIndependent lookups and source reports
PD-20260106-D8B8F9 Recipient: abuse@dnsale.com Victim safety and official reportingImmediate actions and verified reporting channels
Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.
Hãy báo cáo với chính quyền địa phương
Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.