Phishing detection: download.vvtoken.top

Binance
https://download.vvtoken.top/apk/BINANCEPOOL.apk Access site
Screenshot
Screenshot of download.vvtoken.top
Investigate
Domain download.vvtoken.top5 CT hosts on apex
URL https://download.vvtoken.top/apk/BINANCEPOOL.apk
Phishunt analysis Beta
21 low suspicionheuristic risk score · not a probability
Why?
  • +5.3 Keyword match
  • +5.1 Site cluster
  • +3.0 TweetFeed
  • +2.3 ASN reputation
  • +1.3 Suspicious TLD
  • +1.1 No CSP header
  • +0.8 Young domain
  • +0.6 Brand impersonation in path
  • +0.6 Registrar reputation
  • +0.5 Young certificate
  • +0.4 Long domain
  • +0.3 Free CA
  • +0.1 Deep subdomain
15 signals fired · detector v3.0.0
AI analysis AIBeta
Malware delivery

Site distributes a trojanized Android APK file presented as a Binance Pool application, likely delivering crypto-stealing or surveillance malware. Hosted on a .top domain via Cloudflare and flagged by TweetFeed threat intelligence. The file path directly references the spoofed brand.

TweetFeedBrand impersonation in pathNo brand links
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-22 · confidence 83%
Domain & Network
Whois
Registrar NameSilo, LLC
Network
Country United StatesUnited States
ASN AS13335
TLS Cert WE1
External detection TweetFeed
CleanGoogle Safe Browsing · OpenPhish · PhishTank · urlscan.io
Report this phishing
Network / ASN Cloudflare, Inc.
Registrar NameSilo, LLC

Tracked from 2026-08-21 21:01 UTC  ·  Last refreshed 2026-08-24 03:30 UTC