phantom-wallet[.]blogspot[.]ch
“Phantom Wallet - A friendly Crypto Wallet”
证据摘要
Analysis shows that phantom-wallet.blogspot.ch is an active brand-impersonation site targeting users of the Phantom crypto wallet. The page title "Phantom Wallet - A friendly Crypto Wallet" directly references the legitimate brand, confirming the impersonation intent. The domain resolves to the IPv6 address 2a00:1450:4001:80f::2001, which belongs to Google LLC (AS15169) and is geolocated in Germany, indicating use of reputable hosting infrastructure to obscure malicious activity. The site presents a 302 redirect and serves content over HTTPS with a certificate issued by Google Trust Services, further lending an appearance of legitimacy. Technical fingerprints reveal the use of Blogger, Java, Python, OpenGSE, and HTTP/3, consistent with a typical compromised or abused blogging platform. VirusTotal reports 12 of 93 security vendors flagging the domain, and the site appears on a single external blocklist, with PhishDestroy already listing it as malicious. While the exact payload or credential‑harvesting mechanism has not been publicly disclosed, the combination of brand‑specific page title, high‑risk classification, and multiple vendor detections warrants a high risk rating. Defenders should block the domain at the DNS and proxy level, monitor for outbound connections to the associated IPv6 address, and update detection rules to flag URLs containing "phantom-wallet.blogspot.ch". Continuous threat‑intel feeds should be consulted for any emerging indicators of compromise tied to this infrastructure.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
检测时间线
-
域名状态
可访问 → 无法访问
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控