الانتقال إلى تقرير الأمان
Checked 09/08/2026 Ref FF5146F6

MALICIOUS — CRITICAL

hyperswaps[.]io

The domain hyperswaps.io was registered on February 21, 2026 and is currently active.

93/100 evidence score · Critical
VirusTotal
11/91
Blocklists
No stored match
التوفر
خطأ في الخادم · HTTP 502
Report / Add Evidence Appeal this listing
2026-02-26 22:21 UTCخطأ في الخادم · HTTP 502

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 11. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
Jump to section
ملخص التقرير

hyperswaps.io — خطأ في الخادم (HTTP 502). نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 11/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 93/100.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

Evidence Analysis

Ref FF5146F6

The domain hyperswaps.io was registered on February 21, 2026 and is currently active. HTTP requests return a 200 status code and the page title is reported as "Hyper Cafe." Infrastructure analysis shows the domain resolves to IP address 217.114.42.81, which belongs to the Russian AS57724 network operated by DDOS-GUARD LTD. The SSL certificate is rated R10 and the site receives a Gridinsoft trust score of 0 out of 100, indicating a lack of credibility. Threat intelligence indicates the site is classified as a generic phishing operation with a specific focus on cryptocurrency scams. It is listed on a single security blocklist and has been blocked by PhishDestroy. AlienVault OTX references the domain in one threat pulse, and VirusTotal reports that 11 of 91 scanning engines flagged the domain as malicious. The risk rating is high and the status remains active. While the available data confirms malicious infrastructure and a crypto‑related scam profile, the exact content of the landing page has not been publicly analyzed, leaving the specific tactics employed uncertain. Defenders should continue to block the domain at network perimeter devices, monitor DNS queries for the 217.114.42.81 address, and consider adding it to internal threat feeds. Ongoing observation of related indicators, such as future blocklist appearances or additional VirusTotal detections, is recommended to refine response actions.

VirusTotal
VirusTotal
11 det.
OTX references
شهادة TLS
منتهية الصلاحية أو غير متحقق منها
العمر
6 mo
الحالة المرصودة
خطأ في الخادم 502
PhishDestroy
قائمة الإتلاف
مُدرج
نطاق تغطية البيانات12 recorded checks
VirusTotal 11 / 91 URLQuery checked — no detections recorded PhishStats لم يتم التحقق منها OTX 1 community reference رادار CF no data URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS لم يتم التحقق منها TLS منتهية الصلاحية أو غير متحقق منها WHOIS 6 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
10/12

حالة قوائم الحظر العامة

لقطة محفوظة

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN ddos-guard · AS57724 DDOS-GUARD DDOS-GUARD LTD, RU
سمعة عنوان IP abuse score 0/100 0 reports checked 15/07/2026
عنوان IP 217.114.42.81 RU
الموقع الجغرافيRU Rostov-na-Donu, RU
الشبكةAS57724 · DDOS-GUARD LTD
التسجيلتم إنشاؤه 21/02/2026 (169d)
حالة HTTP502 Error
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف26/02/2026
DOM Analysisanalyzed 09/07/2026score 93/100
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
عنوان الصفحة
Hyper Cafe
شهادة TLS
منتهية الصلاحية أو غير متحقق منها · صادرة عن R10
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

11 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed Previous stored snapshot: 11 detections
ADMINUSLabs
alphaMountain.ai
BitDefender
CRDF
CyRadar
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Lionic
سوفوس
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك
تضمين هذا التقريرRead-only HTML widget
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/hyperswaps.io"
  title="PhishDestroy threat report for hyperswaps.io"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>