Skip to security report
Domain security and threat intelligence
bsw.online favicon

bsw.online

“Trojan - The Ultimate On-Chain Trading Experience”

Threat verdict Critical 100/100 evidence score
Availability Cloaked · reachable Reachability observed through cloaking checks
VirusTotal detections: 13/91 Stored blocklist matches: 2 Scam type: Crypto Drainer Last known active
Apr 20, 2026 CDN
Actions API
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 13. Public blocklists reporting a match: 2. Exercise extreme caution — do not enter credentials or personal information.

Evidence Summary

CRITICAL
Score
100/100

PhishDestroy identifies bsw.online as an active crypto drainer masquerading as a legitimate on-chain trading platform, as confirmed by its title 'Trojan - The Ultimate On-Chain Trading Experience'. This domain was specifically engineered to trick users into connecting cryptocurrency wallets and draining funds through deceptive smart contract interactions. The page promotes fraudulent 'on-chain trading' services while operating solely to exploit unsuspecting victims through malicious on-chain transactions. Security vendors widely recognize this threat, with 6 of 95 VirusTotal scanners already detecting its malicious nature, and major platforms like MetaMask and SEAL have preemptively blocked access to this domain. Technical analysis reveals this domain exhibits multiple red flags consistent with crypto drainer infrastructure. Registered on November 16, 2025 through NAMECHEAP INC, the domain resolves to IP address 104.21.54.42 and leverages a Let's Encrypt SSL certificate to appear legitimate. Notably, this domain has already been identified by four major security blocklists including OISD and Maltrail, demonstrating widespread recognition across the security community. The combination of recent domain registration, association with known malicious infrastructure, and active blocking by security solutions confirms this is not a false positive but rather part of an emerging campaign targeting cryptocurrency users. If you've visited bsw.online, disconnect your wallet immediately and revoke any permissions you may have granted. Check your wallet transaction history for any unusual outgoing transfers and report suspicious activity to your security team. Consider transferring remaining funds to a new wallet with enhanced security measures. Enable wallet protection features like transaction simulation if available, and remain vigilant for follow-up phishing attempts. Monitor your devices for potential malware infections that may have resulted from this interaction.

VirusTotal
VirusTotal
13/ 91 vendors
DNS Security
3/ 12 providers
URLScan
URLScan
TLS Certificate
Let's Encrypt
Age
10 mo
Observed status
Cloaked · reachableHTTP 403
PhishDestroy
DestroyList
ListedBlocklist
Data coverage 11/13 sources checked · 2 flagged VirusTotal 13 / 91 URLQuery not checked PhishStats checked — no match recorded OTX no community references CF Radar scan completed URLScan capture stored report URLScan verdict Analysis completed DNS blocks 3/12 Spamhaus DBL not listed at check TLS valid certificate, 79d WHOIS 10 mo old Screenshot 2 captures · 2 sources Redirect chain not probed
Network Security Intelligence
DNS Provider Blocks 3 / 12
Controld Adblock Controld Family Controld Malware

Financial Infrastructure

Addresses extracted from the phishing page.

Telegram

Threat Response Pipeline

Discovery
Checks
Reports
Availability
11/13

Public Blocklist Status

Blocklist coverage

11 monitored external feeds · stored snapshot Sep 11, 2026

9 monitored external feeds No match

Stored detection

Cloaking alert

Cloaking type
content_divergence
Cloaking score
2/6
Scanner-facing titleDNS points to prohibited IP | bsw.online | Cloudflare
Visitor-facing titleTrojan - The Ultimate On-Chain Trading Experience

Stored Capture · 2 sources

Page Title
Trojan - The Ultimate On-Chain Trading Experience
TLS Certificate
Valid transport encryption · Issued by Let's Encrypt · valid for 79 days

Domain Intelligence

Domain
URLScan Verdict Analysis completed score 0 report ↗
Telegram IoCs
1 extracted
Server / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Edge-IP reputation is not attributed to this domain.
Registrar Namecheap SE(SE)
IP Address 104.21.54.42 CDN
GeoCA Toronto, CA
NetworkAS13335 · Cloudflare, Inc.
The origin IP is hidden behind a CDN proxy. Reverse-IP results for the edge address contain unrelated tenants; finding the origin requires passive DNS or certificate-transparency data.
RegistrationCreated Nov 16, 2025 (299d)
HTTP Status403 Forbidden
Cloaking Cloaking Detected Content divergence · score 2/6
alive_content: raw=waf_403; http=403; via=https_proxy; server=cloudflare
server: cloudflare title: DNS points to prohibited IP | bsw.online | Cloudflare
checked Sep 11, 2026
Technical detailsDNS, SSL SANs, timestamps
First DetectedApr 20, 2026
IoC Extractionscanned Jul 29, 20260 wallet · 1 Telegram IoC
Submitted URLhttp://bsw.online/
Nameserversezra.ns.cloudflare.comjocelyn.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from May 20, 2026scanned Jul 9, 2026
ICANN OVERSIGHT

Accreditation and RAA context

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nothing is sent automatically.
Technologies · 6 high-confidence technologies identified
Stack profile JavaScript frameworks 2 Programming languages Analytics RUM CDN Miscellaneous
Detected via Cloudflare Radar · Wappalyzer engine · stored snapshot, not a live probe Cloudflare Radar
Report This Domain Submit evidence & help protect others

VirusTotal Analysis · stored analysis

13 / 91 security vendors flagged this domain
View on VirusTotal
Last analyzed Previous stored snapshot: 14 detections
alphaMountain.ai
BitDefender
Chong Lua Dao
CyRadar
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Lionic
SOCRadar
Sophos
VIPRE
Site Performance Analysis

Google PageSpeed Insights — mobile performance audit of bsw.online · checked Apr 20, 2026

65
Needs Work
Performance
FCP
4.35s
First Contentful Paint
LCP
5.55s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
151ms
Total Blocking Time
SI
5.25s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Community reports

Reported by 1 community member, first seen Apr 20, 2026

Stored reports
1
Unique reported URLs
1
Accepted1

Evidence & External Reports

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing
HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/bsw.online"
  title="PhishDestroy threat report for bsw.online"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

A Very Sincere Thank-You Note

Satirical draft generator

Recipient
Fee context

Satirical draft. Fee figures are estimates; exact attribution to this domain is not claimed.