changenow-swap[.]org
“ChangeNOW”
changenow-swap.org — Inhalt nicht verfügbar. Markenidentität: Across; Betrugstyp: Wallet/seed Phishing. Zusammenfassung der Beweislage: VirusTotal 19/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, Certego, CRDF); Spamhaus DBL_PHISH; 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 100/100. Registrar: CSL Computer Service L….
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain, changenow-swap.org, poses a direct financial threat as a crypto drainer targeting users of the Across protocol through brand impersonation. The site mimics the legitimate ChangeNOW platform, presenting a fraudulent interface designed to trick victims into connecting wallets and authorizing transactions that siphon funds to attacker-controlled addresses. Infrastructure analysis reveals the domain was specifically crafted to exploit trust in cross-chain swap services, a tactic increasingly observed in targeted attacks against decentralized finance users.
Evidence confirms the malicious nature of changenow-swap.org through multiple technical indicators. The domain is flagged by 19 out of 95 security vendors on VirusTotal, with detections spanning phishing, malware distribution, and fraud categories. It appears on seven distinct security blocklists, including those maintained by wallet security providers and threat intelligence platforms. Registered on October 29, 2025, through CSL Computer Service Langenbach GmbH d/b/a joker.com, the domain resolves to IP address 91.92.243.31, hosted on AS202412 Omegatech LTD in the Netherlands. The SSL certificate (serial number E8) and page title 'ChangeNOW' further align with known impersonation patterns used in crypto drainer campaigns.
Users who visited changenow-swap.org or interacted with its content should immediately revoke any wallet authorizations granted to the site. Check connected applications in wallet settings and remove suspicious entries, particularly those requesting unlimited spend permissions. Scan devices for malware using updated security tools, as some drainer campaigns deploy secondary payloads. Monitor wallet activity for unauthorized transactions and consider migrating funds to a new address if compromise is suspected. Report the domain to relevant security teams and wallet providers to aid in broader mitigation efforts. Given the high-risk classification and offline status, remain vigilant for similar domains using slight variations of the brand name or swap-related terminology.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Forensische Erkenntnisse
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt