DANGEROUS

Brand impersonation — not the real site

5 of 92 antivirus engines flag this page as malicious. This page is styled as a brand but is not the brand's real site. Go to the official site directly, and treat any download, login, or payment request here as unsafe.

Security Review

Is wintermute-prime.com legit or a scam?

Our verdict:Dangerous· 1/100

Fake Wintermute USDC Prime vault that is a 5-day-old typosquat clone flagged as a crypto drainer by multiple engines and reports.

wintermute-prime.comScanned 12d ago
0
Trust score
DANGEROUS
Heuristics 0·MT 10
Category tags
phishingcrypto#Phishing#Crypto Fraud#Clone Site95% MT confidence

These checks passed — but they don't clear the site. A clean antivirus result, valid SSL, and a calm server only mean it isn't hosting malware; they say nothing about whether the business is real. This verdict is based on the site's conduct and content, not a malware detection.

View density

Analysis Summary

Threat Intelligence
0/92
Engines flagged this URL
Domain Age
5 days old
Registered May 19, 2026
MT Intelligence
Dangerous
Critical likelihood · 95% confidence

MT Intelligence

Advanced threat intelligence
MT Security Analyst
Critical scam likelihoodengineMT · Guardiantrust10/100
MT AgentLive web researchVisual inspectionNetwork correlation
0%
Confidence
The page presents itself as a legitimate Wintermute vault interface with deposit figures and APY charts, but the domain wintermute-prime.com was registered only five days ago. Five engines from our antivirus network flagged the site for phishing or malware, and our scam network fingerprint confirms it is both a clone and typosquat of the real wintermute.com. A report from PhishDestroy explicitly identifies it as a crypto drainer impersonating Wintermute Finance, with no business registration or positive mentions found anywhere. The combination of extreme newness, direct impersonation, and external scam confirmation leaves no reasonable doubt about its intent.
Full dossier
Analysis complete

Page Content

The site displays vault statistics for a supposed Wintermute USDC Prime V2 product on Morpho, including TVL figures, APY charts, and a wallet address. No contact details, company address, or legitimate footer links appear.

Infrastructure

Hosted on IP 172.67.152.17 with clean abuse scores and valid Let's Encrypt SSL. The domain itself is only five days old through registrar Fewmoretaps OU.

Domain History

WHOIS shows a brand-new registration with no prior history. The name directly mimics wintermute.com while adding a hyphen and extra word.

Web Reputation

One confirmed scam report labels it a crypto drainer. No business records, reviews, or legitimate mentions exist for this domain.

Risk Factors
5
  • Domain created only 5 days ago with no business history
  • Multiple antivirus engines flag the page as phishing and malware
  • Exact clone and typosquat of the real wintermute.com
  • Explicitly reported as a crypto drainer on PhishDestroy
  • No contact information or verifiable company details present
Positive Signals
2
  • IP address shows zero abuse reports
  • SSL certificate is currently valid
AI Recommendation
Avoid this site completely. Visit only the official wintermute.com if you need Wintermute services and never connect a wallet to unverified domains.
Scam network detected
1 linked domain correlated

Evidence confirms this site is a clone and typosquat of wintermute.com.

wintermute.com
Next-gen fraud intelligence
Evidence-backedCross-checked

Website Preview

Screenshot of wintermute-prime.com
LIVE RENDER
wintermute-prime.com

Automated page render — captured in a safe sandbox. What an ordinary visitor would see when loading the site.

Web Research Findings

Our live research agent queries scam-report databases, consumer-review sites, news coverage, and general web search for wintermute-prime.com, then cross-checks business-registration records and look-alike domain patterns. Everything below is pulled from what it actually found.

Domain age
5 days
Registered May 2026
Business registration
No public record found
Could not match the site to a registered company — common for small sites.
Clone check
Clones wintermute.com
The page impersonates a well-known brand's site.
Typosquat check
Typosquat of wintermute.com
Deliberate misspelling of a real brand's domain.
Web mentions
1 scam report
Key findings
6 headline facts from open-web research
  • Domain wintermute-prime.com is 5 days old.
  • Page content titled 'Morpho | Wintermute USDC Prime vault' with vault address 0x5dc53a23AdC9f2Bed98de6F59F7F309a7c71FF2B.
  • Flagged as crypto drainer impersonating Wintermute Finance on PhishDestroy.io (flagged by MetaMask and SEAL).
  • Legitimate Wintermute operates at wintermute.com as an established algorithmic trading and liquidity provider founded in 2017.
  • No business registration, positive reviews, or legitimate mentions of wintermute-prime.com found in searches.
  • Multiple search results link the domain directly to scam alerts alongside other flagged crypto-related domains.
Scam reports (1)
Direct quotes from public scam databases, forums, and news.
  • PhishDestroyopen

    "wintermute-prime.com is a crypto drainer impersonating Wintermute Finance. Flagged by MetaMask and SEAL, verified on PhishDestroy."

Impersonation / typosquat
Typosquat of wintermute.com

Domain hosts content impersonating Wintermute USDC Prime vault on Morpho; real Wintermute site is wintermute.com

Research summary
Narrative write-up from our AI analyst, grounded on the facts above
PhishDestroy reports wintermute-prime.com as a crypto drainer impersonating Wintermute Finance, with flags from MetaMask and SEAL. No business registration or positive mentions appear in any searched sources. The legitimate Wintermute operates at wintermute.com since 2017.

Scam Network Intelligence

Cross-site correlation

This site shares signals with a broader cluster

Critical cluster

Many scams don't operate alone. We correlate third-party scripts, hosting infrastructure, brand-impersonation signals, and the AI evidence package to detect when a site is part of a broader scam network.

Suspicion score
0/100
ClearLowModerateHighCritical
Evidence (3)
  • Evidence confirms this site is a clone of wintermute.com.
  • Domain is a typosquat of wintermute.com.
  • Domain is only 5 days old and already carries multiple network-level red flags.
Linked signals (2)
Clone of wintermute.comTyposquat of wintermute.com

Antivirus Engines

Detection matrix · live
7 engines flagged this URL

We cross-check every URL against our antivirus network of 92 malware and blacklist engines. Each detection is listed below by engine name — even a single hit is a meaningful signal.

5Malicious2Suspicious53Harmless92Engines
0
of 92
BitDefender
Malicious· phishing
Forcepoint ThreatSeeker
Malicious· phishing
G-Data
Malicious· phishing
Kaspersky
Malicious· phishing
Sophos
Malicious· malware
ESET
Suspicious· suspicious
Gridinsoft
Suspicious· suspicious

7 antivirus engines flagged this URL. Even a single detection is a meaningful signal — treat this site with extra caution and avoid entering credentials, payment info, or downloading any files.

Security Scans

Blacklist Check
Not flagged on major threat lists

Checked against the major public blocklists used by browsers and security tools — no hits.

Contact Verification

We fetched the page and looked for real-world contact details. Legitimate businesses almost always publish an email on their own domain, a phone number, and a postal address. Scam shops usually don't.

What We Found
No clear contact details on the page
Emails on site's domainNone
Phone numbers2026-04-22
Postal addressNot listed
Linked social profiles0
Signal Summary
Several contact red flags
  • No contact email found anywhere on the page.
  • No postal address visible on the page.
  • Phone number listed (2026-04-22).

Domain & Encryption

Domain History
Age5 days old
RegistrarFewmoretaps OU d/b/a Trustname.com
RegisteredMay 19, 2026
ExpiresMay 19, 2027
Owner privacyVisible
Encryption Certificate
StatusValid
ProtocolTLSv1.3
IssuerLet's Encrypt · E8
ExpiresAug 17, 2026 (84d)
Self-signedNo
Hosting & Technology
HostingCloudflare, Inc.
Server locationUS

Server Reputation

Abuse Intelligence
Confidence score0%
Reports on file0
ISPCloudflare, Inc.
Usage typeContent Delivery Network

Scam-Type Likelihood

3 scam-type patterns detected
Scam-Type Likelihood

0 of 13 categories showed signals

We check every URL against 13 distinct scam categories so the verdict tells you not just how risky the page is, but what kind of risk it carries. Each meter pulls from page signals, web reports, our AI analyst, vision, and the scam-network cluster — not from raw AV labels.

Top match: Brand Impersonation
Brand Impersonation
Moderate likelihood
0/100
  • Domain is a typosquat of wintermute.com.
  • AI analyst tagged this as a brand / clone-site impersonation.
  • Clustered with known brand-impersonation infrastructure.
Phishing
Moderate likelihood
0/100
  • Domain is a typosquat of wintermute.com.
  • AI analyst tagged this as phishing.
Crypto Fraud
Moderate likelihood
0/100
  • AI analyst tagged this as crypto fraud / wallet-drainer.
  • AI analyst categorised the site as crypto-themed.

Brand impersonation detected

This page is styled as a known brand but is not the brand's real site.

  • Do not interact with wintermute-prime.com

    Do not enter credentials, deposit money, download files, or install browser extensions from this site.

  • Go to the brand's real site directly

    Type the brand name into a search engine or open it from your bookmarks — don't use links from emails, SMS, ads, or social posts, which are the delivery vectors for impersonation.

  • Never download or sign in here

    Even if the page "just" offers a download or a giveaway, impersonation pages frequently deliver malware or set up follow-up phishing. Assume anything accepted from this site is hostile.

  • Report the impersonation to the brand

    Most major brands have a dedicated abuse or anti-phishing reporting channel — reporting helps them take the site down and protects other users.

    Open

Reputation Sources

How this domain rates across independent threat-intelligence and blocklist providers.

Google Safe Browsing
Not listedCheck ↗
VirusTotal
ListedCheck ↗
AbuseIPDB
Not listedCheck ↗

Referenced Domains

Outbound domains this page links to or loads resources from. Each links to its own security scan.

Safety FAQ

Common questions about this site, answered from the scan data on this page. These are auto-generated — not hand-written — so they always match the underlying report.

  • Our automated security review flags wintermute-prime.com as dangerous. Multiple threat indicators were detected — treat the site as a scam until proven otherwise.

Final Verdict

0
Trust / 100
Final Verdict·wintermute-prime.com
DANGEROUS

This site impersonates a Wintermute USDC Prime vault on Morpho. Our verdict is malicious because the domain is only 5 days old, five antivirus engines flag it as phishing or malware, and it has been reported as a crypto drainer. Do not connect any wallet or interact with the page.

Avoid this site completely. Visit only the official wintermute.com if you need Wintermute services and never connect a wallet to unverified domains.

AV engines
92
MT passes
2
Net signals
2
Scan another URL
Security review completemalwaretips.com/url-scan
Recently scanned

Other Dangerous reports

Browse all reports
Community review

User reviews & comments(0)

Share your experience — "Lost $200 on a fake checkout" is more useful than "Scam". Your review helps others avoid traps.

Loading…
Loading comments…
Scanned by
JackStaff
This report is generated automatically by combining threat intelligence, domain signals, and an AI security analyst. It is informational, not legal advice. Always use your own judgement before sharing personal information or money online.