sushi-ena[.]top
“Stake SUSHI | Sushi”
sushi-ena.top — Inhalt nicht verfügbar (HTTP 502). Markenidentität: SushiSwap; Betrugstyp: Crypto Scam. Zusammenfassung der Beweislage: VirusTotal 6/93 (alphaMountain.ai, BitDefender, CyRadar, Fortinet, G-Data); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 74/100.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
The domain sushi-ena.top was registered on February 21, 2026 and is currently listed as offline. DNS resolution points to the IPv4 address 107.172.83.150, which belongs to the HostPapa hosting provider (AS36352) and is geolocated in the United States. An SSL certificate identified as R11 is present on the site, indicating that HTTPS was configured before the domain was taken down. The page title returned by the server is "Stake SUSHI | Sushi," which aligns with the declared scam type of a crypto scam targeting users of the SushiSwap platform.
The domain is specifically marked as impersonating SushiSwap, a well‑known decentralized exchange, and therefore falls under the brand‑impersonation threat category. Detection data show that six of ninety‑three security vendors on VirusTotal flagged the domain, suggesting a moderate level of malicious confidence among scanners. The domain appears on four independent blocklists—PhishDestroy, Polkadot, Enkrypt, and Codeesura—demonstrating that multiple threat‑intelligence feeds have recognised it as abusive. No additional public intelligence, such as OTX or Safe Browsing entries, is available beyond the listed blocklist memberships.
Given the limited exposure window (the domain was active for only a few months before being taken offline) and the lack of publicly disclosed payload or credential‑harvesting mechanisms, the precise operational details of the campaign remain uncertain. Defenders should update their URL filtering and DNS sink‑hole rules to include sushi-ena.top, monitor the hosting provider’s IP range for related activity, and consider the six VirusTotal detections as a signal to prioritize related alerts. Continuous observation of the associated IP address and any future registrations under the same registrar is recommended to detect potential re‑use of the infrastructure for further brand‑impersonation attempts.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt