imtaken[.]cc
“imToken official website|Ethereum and Bitcoin blockchain wallet”
证据摘要
The domain imtaken.cc was registered on 21 February 2026 and is presently hosted on the IP address 20.247.100.105, which resolves to a Microsoft Corporation network (AS8075) located in Hong Kong. The site’s TLS certificate is identified as R13, indicating a publicly trusted certificate without obvious anomalies. The page title returned from the HTTP response reads "imToken official website|Ethereum and Bitcoin blockchain wallet", a clear reference to the imToken cryptocurrency wallet service, while the threat intelligence tags list the brand target as Arbitrum. This mismatch between the page title and the claimed impersonated brand suggests a deliberate brand‑impersonation tactic aimed at users of the Arbitrum ecosystem.
Open‑source threat feeds corroborate the malicious nature of the domain. AlienVault OTX includes the domain in one pulse, and VirusTotal reports that 20 of 93 security vendors classify the host as malicious, a proportion that exceeds typical background noise for benign sites. The domain appears on a single security blocklist and is explicitly blocked by the PhishDestroy service, reinforcing the assessment that it is being used for a crypto‑related scam. The current HTTP status is reported as offline, meaning the site is not presently serving content, which limits real‑time verification of the exact payload but does not negate the historical evidence of abuse.
Defenders should continue to block imtaken.cc at the DNS and proxy layers, and add the associated IP range to network‑level deny lists. Because the infrastructure resides on a Microsoft‑owned AS, contacting the provider’s abuse team with the full set of indicators (domain name, IP address, registration date, detection counts, and blocklist references) may expedite takedown. Continuous monitoring of passive DNS and certificate transparency logs is advised to detect any re‑registration or reuse of the same IP address by related threats.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控