phantom-wallet[.]duckdns[.]org
“phantom-wallet.duckdns.org”
phantom-wallet.duckdns.org — 未验证. 品牌冒充:Across; 诈骗类型:Wallet/seed Phishing. 证据摘要: VirusTotal 15/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); URLScan malicious verdict; PhishDestroy score 95/100. 注册商: DuckDNS.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, phantom-wallet.duckdns.org, is flagged for brand impersonation, a high-risk threat where malicious actors create a website that mimics a legitimate brand to deceive users. The impersonation is designed to trick visitors into revealing sensitive information or performing actions that could compromise their security.
Analysis indicates that phantom-wallet.duckdns.org was created on February 21, 2026, and has been flagged by 14 out of 95 security vendors on VirusTotal. The domain is registered through DuckDNS, a free dynamic DNS service, which can be a red flag as it is often used for temporary or illicit activities. Additionally, the domain resolves to an IP address, 103.186.31.94, located in Indonesia and is associated with AS141892 CV Andhika Pratama Sanggoro. The site also appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL, further confirming its malicious nature.
If a user has visited this site, they should take immediate steps to ensure their security. First, they should change any passwords or sensitive credentials that may have been entered on the site. Users are advised to monitor their accounts for any unauthorized activity and to enable two-factor authentication (2FA) for added security. It is also recommended to run a full system scan using reputable antivirus software to detect and remove any potential malware. Users should report the incident to the legitimate brand, across, and to their respective financial institutions if any financial information was compromised.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。