http://privacnote.com/notes
62.60.226.244 · Femo IT Solutions Limited
Frankfurt am Main, Germany
4 days ⚠
200 · 13.0s
Valid· R13, Let's Encrypt, US
COMPLETED
Domain Intelligence: privacnote.com
Scanned 2 times since Apr 12, 2026, 11:44 AM UTC
Linked Phishing Report
This scan is attached to a vendor submission report
Brand
Privnote
Vendors
30/30
Status
completed
Privnote Clone Kit
privnote-clone-kit
Directives: skipAi, skipUnblocker, skipMobileVariant
Cryptocurrency · 4/15/2026
This page is a clone of Privnote built from a known phishing kit. It reproduces the exact Privnote UI structure and branding on a non-official domain. These clones are used for cryptocurrency theft — they intercept or replace wallet addresses in notes that victims share, sometimes exfiltrating data via Telegram webhooks. The domain is not affiliated with the legitimate privnote.com.
Capture
Stages: 2
Canonical: Settled Render
Changed: No
Credential Signals
Forms: 1
Password fields: 3
Late-stage login UI: No
Resource Signals
Resources: 9
Hosts: 1
Domains: 1
Suspicious Endpoints
hxxp://privacnote[.]com/notes/
hxxp://privacnote[.]com/notes/api/send.php
This domain serves a known Privnote clone kit identified by its HTML structure and branding assets. These kits are deployed across many typosquat domains and are used for cryptocurrency theft — typically by intercepting or replacing wallet addresses in shared notes. The kit is not affiliated with the legitimate privnote.com service. This is a confirmed malicious deployment that warrants immediate domain suspension and hosting takedown.
Suspend Domain