photondao[.]ws
“photondao.ws”
photondao.ws — 未验证. 品牌冒充:MetaMask; 诈骗类型:Impersonation. 证据摘要: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 88/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
On July 29, 2026, the domain photondao.ws was classified as a generic phishing threat with an elevated risk rating and remains active. VirusTotal analysis shows that four of ninety‑one security vendors have flagged the domain, indicating partial detection across the scanning ecosystem. The domain is listed on three independent security blocklists and is actively blocked by the PhishDestroy, MetaMask, and SEAL blocklist providers, reinforcing its malicious reputation.
Network resolution points to the IPv4 address 91.195.240.123; no additional hosting details were disclosed. The presence of the domain on multiple blocklists and the partial vendor detections suggest a coordinated infrastructure that is already being leveraged for credential‑harvesting campaigns. However, the absence of publicly available page title, SSL certificate details, or HTTP response codes limits the current visibility into the exact phishing vector or targeted brand.
Consequently, the precise content and lure employed by the site cannot be confirmed at this time. Defensive teams should prioritize immediate sink‑hole or deny‑list actions for photondao.ws and its resolved IP address, incorporate the domain into existing phishing detection rules, and monitor for any ancillary indicators such as DNS changes or additional IP associations. Ongoing telemetry collection and periodic re‑scanning with VirusTotal or comparable services are recommended to capture potential changes in vendor detection rates and to assess whether the domain expands its operational footprint.
威胁响应 Pipeline
公共封禁名单状态
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
证据与外部报告
“On June 1, 2026, a phishing link (https://photondao.ws/mint) was posted in the Moonwalk Community Telegram group (2,470 members). I clicked the link and connected my Solana wallet. A malicious smart contract automatically drained my entire wallet without my explicit approval. Assets stolen: 2.08479 SOL, 10,000 CONE tokens, 1 PIP token. My wallet (victim): HSBZSX6qoreQgdvVhQGLVJ8qAdU9UobnNxLxE6NqWBfs. Hacker wallet: AEARtPTM97o2uBbMtJ1w5GF7LW1H94cqPUYQCR1Sus5a. Funds transferred to: 2L9futG8Z82Mp”
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。