typhondesktop[.]io
“Typhon Wallet”
证据摘要
Analysis of typhondesktop.io shows a newly registered domain (creation date October 09, 2025) that was taken offline before the report date of July 23, 2026. The domain resolves to the IPv4 address 216.198.79.65, which is hosted in the United States under ASN16509 (Amazon.com, Inc.). No TLS certificate is presented, indicating that the site operated without HTTPS. The authoritative name servers are ns1.vercel-dns.com and ns2.vercel-dns.com, suggesting use of Vercel's DNS service for fast deployment. The registrar listed is HOSTINGER operations, UAB.
The page title captured from the site reads "Typhon Wallet", and the threat is classified as a Wallet/Seed Phishing campaign that impersonates the Ledger brand. VirusTotal scans returned 16 detections out of 95 security vendors, demonstrating a moderate level of consensus among scanners that the domain is malicious. The domain appears on a single public blocklist, PhishDestroy, which has already flagged it for distribution to protective services. Gridinsoft assigns a trust score of 0 out of 100, reinforcing the malicious assessment. The absence of SSL, the low trust score, and the presence on a phishing blocklist collectively confirm the domain's intent to harvest cryptocurrency wallet credentials.
Defenders should ensure that the IP address 216.198.79.65 is blocked at perimeter firewalls and that any outbound connections to this address are logged. DNS queries for typhondesktop.io should be intercepted or redirected to a sinkhole to prevent future resolution. Monitoring should be extended to other domains registered through HOSTINGER operations, UAB and to any new domains that resolve to the same Amazon AS16509 range, as threat actors often reuse infrastructure. Because the site is currently offline, real‑time content analysis is not possible; however, the existing indicators—page title, brand impersonation, detection count, and blocklist entry—provide sufficient evidence for a proactive defensive posture.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月10日
检测时间线
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控