imtoken-ledger[.]com
imtoken-ledger.com 网络钓鱼与安全检查
“imToken official website|Ethereum and Bitcoin blockchain wallet”
imtoken-ledger.com — 内容不可用 (HTTP 502). 品牌冒充:Arbitrum; 诈骗类型:Wallet/seed Phishing. 证据摘要: VT 15/93 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); URLQuery 10 alerts; URLScan malicious; GSB no flag; BL 0; PD 100/100. 注册商: Dominet (HK).
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy first observed imtoken-ledger.com on Feb 3, 2026. The current evidence record is rated critical at 100/100. 3 independent sources recorded positive findings: VirusTotal, URLQuery, and URLScan.
VirusTotal recorded 15 detections among 93 engines: alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Kaspersky, Lionic, Seclookup, SOCRadar, Sophos, VIPRE, Webroot on May 16, 2026 at 15:58 UTC. URLQuery recorded 10 threat-system alerts on Feb 3, 2026 at 21:47 UTC. URLScan returned a malicious verdict with score 100 on Mar 26, 2026 at 12:29 UTC. The external blocklist snapshot contained no matches on Aug 7, 2026 at 14:20 UTC. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC. PhishStats returned no feed match on Mar 3, 2026 at 08:06 UTC.
HTTP 502 was recorded on Aug 7, 2026 at 01:17 UTC; content was unavailable. Registration records for the domain list Dominet (HK) Limited as the registrar. At collection time, the domain resolved to 20.247.100.105 on AS8075 (MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation, US). The stored server header is nginx. Collected metadata identifies Arbitrum as the apparent target. Captured page title: “imToken official website|Ethereum and Bitcoin blockchain wallet”. PhishDestroy classified the observed content as Wallet/seed Phishing. DOM analysis completed on Apr 23, 2026 at 03:22 UTC; stored DOM score 70/100. IoC extraction completed on Aug 2, 2026 at 04:14 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
A stored capture reference is available for visual review.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | m.imtoken-ledger.com |
malicious | Sinkholed |
| OpenDNS | m.imtoken-ledger.com |
phishing | Phishing Block |
| DNS4EU | m.imtoken-ledger.com |
malicious | Sinkholed |
| DigiCert UltraDNS | imtokens.co |
malicious | Sinkholed |
| DNS4EU | imtokens.co |
malicious | Sinkholed |
| Cloudflare DNS | imtokens.co |
malicious | Sinkholed |
| Quad9 DNS | imtokens.co |
malicious | Sinkholed |
| Cloudflare DNS | imtoken-ledger.com |
malicious | Sinkholed |
| OpenDNS | imtoken-ledger.com |
phishing | Phishing Block |
| DNS4EU | imtoken-ledger.com |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
ICANN 收到了钱。问责却没有到来。
对于这个 gTLD,上述注册商依据与 ICANN 签订的合同运营。ICANN 收取与注册、续费和转移相关的年度费用、浮动费用及按交易计收的费用。
认证:已变现。问责:请稍后再来查看。
接着,魔法开始了:ICANN 写下 RAA §3.18,注册商调查自身客户群体内部的滥用行为,受害者免费提交证据,而每一层都在等待其他人采取行动。如果这能让受害者觉得更安全,那真是太好了——看来账单确实起作用了。
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。