Analysis of coin-swap.sbs shows a high‑risk, active phishing infrastructure. The domain was registered on July 30, 2026 through NicNames, Inc and is served by Cloudflare nameservers bonnie.ns.cloudflare.com and gordon.ns.cloudflare.com. DNS resolution points to the IP address 188.114.97.3, a Cloudflare edge node commonly leveraged for fast‑flux and anonymisation.
The site appears on three independent security blocklists and is explicitly blocked by PhishDestroy, MetaMask, and SEAL, indicating that multiple anti‑phishing services have observed malicious activity tied to the domain. VirusTotal scanned the domain with 91 vendor engines; none of the engines raised a detection at the time of analysis, but the absence of a flag does not constitute a safety assurance. The domain’s age—registered only days before the report date—combined with its immediate appearance on blocklists suggests a purpose‑built phishing campaign rather than a compromised legitimate site.
No public SSL certificate details, HTTP response codes, or page title information are available, leaving the exact content and lure technique unverified. Defenders should treat coin-swap.sbs as malicious, block network traffic to its IP and associated hostnames, and add the domain to internal deny lists. Monitoring for any future changes in DNS records, SSL issuance, or content signatures is recommended, as the threat actor may later modify the site to evade detection.