imtokew.vip
Categoría: Phishing
Para usar el producto con todas las funciones, debe comprar una licencia de Combo Cleaner. Hay una prueba gratuita limitada de siete días. Combo Cleaner es propiedad de y está gestionado por RCS LT, la empresa matriz de PCRisk.com.
Quttera Web Malware Removal es un servicio de suscripción de pago. Los precios, planes y disponibilidad de prueba los establece Quttera. Quttera es operado por Quttera Ltd, una empresa tercera independiente no relacionada con RCS LT. PCrisk.com puede recibir una comisión por referencia cuando los usuarios se registran a través de este enlace.
Descripción de imtokew.vip
The website appears to present itself as imToken, a cryptocurrency wallet platform focused on Ethereum, Bitcoin, and broader Web3/DeFi asset management. Based on the page title, meta description, and screenshot, it claims to offer non-custodial wallet services, token storage, swapping, staking, and multi-chain support for digital assets such as BTC, ETH, TRX, BNB, and TON.
However, the scanned domain is imtokew.vip, which does not match the brand name shown on the page and may be attempting to resemble the legitimate imToken brand. The site appears to be operated through a recently registered standalone domain rather than an obviously established official brand domain, which is a relevant context point when assessing a crypto-related service that asks users to trust wallet software or connect digital assets.
Evaluación de seguridad de imtokew.vip
This domain was flagged by 14 out of 94 security engines at the time of the scan, with multiple detections indicating phishing or malicious behavior. In addition, the malware scan reported a malicious result and identified one flagged page element. The domain is also extremely new, with a registration age of only 24 days, and it has no meaningful popularity ranking, both of which can be risk indicators for short-lived phishing infrastructure.
The page content closely resembles the imToken cryptocurrency wallet brand, but the domain name imtokew.vip differs from the expected brand spelling and may be a look-alike intended to mislead visitors. In cryptocurrency contexts, this kind of brand resemblance can be especially concerning because users may be prompted to connect wallets, enter seed phrases, or download software. Although one blacklist source reported the domain as clean and some databases had not yet listed it, fresh phishing pages are not always broadly indexed immediately.
Based on these findings, this website may pose potential risks to visitors.
Descripción técnica
The site uses a valid Let's Encrypt TLS certificate, which indicates encrypted HTTPS transport was available at the time of the scan, but a valid certificate alone does not establish legitimacy. The domain is hosted on AWS EC2 in the us-west-2 region using IP address 52.37.165.222, with Dynadot nameservers and DNSSEC reported as unsigned.
From an infrastructure perspective, the combination of a very recently created domain, generic cloud hosting, unsigned DNSSEC, and a short-lived certificate profile is consistent with low-friction deployment. The malware scan also reported a flagged object associated with page content referencing walletconnect.com, which may indicate suspicious use of wallet-connection functionality or abuse of recognizable crypto-related components at the time of analysis.
Comparta su experiencia con este sitio web. ¿Era seguro? ¿Tuvo algún problema?