phantomwnallet[.]webflow[.]io
“Phantom Wallet - Connect Your Wallet - Phantom”
已存储的观测记录
观测到的标题差异
证据摘要
The domain phantomwnallet.webflow.io was observed delivering a crypto‑scam impersonating the Phantom wallet service. Registration records show the domain was created on 08 May 2013 and is listed under the MarkMonitor, Inc. registrar, a provider commonly associated with legitimate brand‑protection services. The authoritative name servers resolve to journey.ns.cloudflare.com and lamar.ns.cloudflare.com, indicating Cloudflare’s DNS infrastructure. DNS resolution points to the IPv4 address 104.18.36.248, which belongs to AS13335 Cloudflare, Inc. and is geolocated to the United States.
TLS termination is performed by a Google Trust Services certificate issued to the WE1 organization, confirming the use of a publicly trusted certificate chain. An HTTP request to the root URL returns a 404 status code, suggesting the site is no longer serving content, and the current status is reported as taken offline. VirusTotal analysis recorded 14 detections out of 95 scanned security vendors, and the domain appears on a single security blocklist where it has been annotated by PhishDestroy as a brand‑impersonation vector. The page title retrieved from the host reads “Phantom Wallet – Connect Your Wallet – Phantom”, directly referencing the targeted brand and aligning with the classified “Crypto Scam” category.
No additional payload or malicious file hashes have been disclosed, and the available evidence is limited to infrastructure and branding attributes. Defenders should continue to block the resolved IP address and the domain name at network perimeter solutions, update URL‑filtering policies to include this FQDN, and monitor for future registrations that reuse the same Cloudflare name‑server pair or similar page titles referencing Phantom. Given the presence of multiple vendor detections and the confirmed brand impersonation, the domain merits an elevated risk rating until the underlying infrastructure is fully mitigated.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
检测时间线
技术
识别出 2 项高置信度技术
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控