sushi-vista[.]xyz
“Stake SUSHI | Sushi”
sushi-vista.xyz — Inhalt nicht verfügbar (HTTP 502). Markenidentität: SushiSwap; Betrugstyp: Crypto Scam. Zusammenfassung der Beweislage: VirusTotal 9/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Forcepoint ThreatSeeker); 1 external blocklist match (ScamSniffer); PhishDestroy score 77/100.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Analysis of sushi-vista.xyz shows a newly registered domain (creation date 2026-02-21) that was used to impersonate the SushiSwap brand. The site presented the page title "Stake SUSHI | Sushi," indicating a focus on the SushiSwap staking service. DNS resolution points to the IP address 107.172.83.150, which is owned by HostPapa (AS36352) and geolocated in the United States. The domain employed an SSL certificate identified as R11, confirming that HTTPS was active at the time of observation.
Threat intelligence aggregators flagged the domain, with nine of ninety‑five VirusTotal scanners labeling it malicious. It appears on two external blocklists and is actively blocked by PhishDestroy and ScamSniffer, both of which categorize the activity as a crypto scam. The domain’s current status is offline, which suggests the operators have taken the site down or moved the infrastructure. However, the existing evidence—brand‑specific page title, IP ownership, SSL usage, and multiple vendor detections—indicates that the domain was deliberately crafted to lure users seeking SushiSwap services, likely to harvest credentials or funds.
Defenders should continue to block the IP address 107.172.83.150 and add sushi-vista.xyz to domain‑based deny lists. Monitoring for re‑registration or similar look‑alike domains is advised, as threat actors often reuse hosting providers and certificate authorities. Organizations that integrate SushiSwap should educate users about the legitimate URL patterns and encourage verification of TLS certificates before interacting with staking pages. The combination of brand impersonation, confirmed crypto‑scam classification, and multiple security vendor detections underscores the elevated risk posed by this infrastructure, even though the site is presently offline.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt