# PhishDestroy threat dossier — defiswap-dex.com ================================================================ Fetched: 2026-07-29 17:06:15 UTC Canonical: https://phishdestroy.io/domain/defiswap-dex.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 67/100 (PhishDestroy scoring — see methodology below) Scam classification: Crypto Drainer Targeted brand: genericcrypto ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 186.2.175.109 (BZ, Belmopan) ASN: AS59692 IQWeb FZ-LLC Hosting org: Iqweb LLC Registrar: Fewmoretaps OU d/b/a Trustname.com !!! REGISTRAR INTEGRITY ALERT — Trustname / Fewmoretaps OU !!! Trustname (IANA #4318) is a shell company declaring EUR 120 annual revenue, 1 employee, negative equity, Belarusian ownership. Explicitly advertises itself as 'bulletproof' in its DNS TXT records. Primary source: https://phishdestroy.io/trustname-bulletproof-exposed Nameservers: ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, zeus.trustname.com Registered: 2026-07-24 Expires: 2027-07-24 Page title: DefiSwap DEX — #1 Swap Platform | Trade, Bridge, Pool HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-10-22 Status: INVALID chain Fingerprint: 0b65c33ae09d2c9ff55da4916c17e0bce450aac4084986c01d129a3bb4e17098 Subject Alternative Names (related infrastructure — often same operator): - www.defiswap-dex.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-24 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-28 19:53:28 UTC (by PhishDestroy tracker) First reported: 2026-07-28 18:10:37 UTC (abuse notice filed) Last verified: 2026-07-29 16:20:22 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa9dc-297b-7558-821d-b09516cc915a/ URLQuery: https://urlquery.net/report/119fac26-6972-4660-8f70-12d3d71af7ad Wayback Machine: https://web.archive.org/web/*/defiswap-dex.com crt.sh CT logs: https://crt.sh/?q=%25.defiswap-dex.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=defiswap-dex.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/defiswap-dex.com URLhaus: https://urlhaus.abuse.ch/host/defiswap-dex.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 19:55:35 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] defiswap-dex.com crypto drainer phishing site — active threat Analysis indicates defiswap-dex.com is an active crypto-drainer phishing domain registered on July 24, 2026, through Fewmoretaps OU operating as Trustname.com. The domain currently resolves to IP address 186.2.175.109 and uses nameservers ares.trustname.com, ns1.anycastdns.cz, ns2.anycastdns.cz, and zeus.trustname.com. As of July 28, 2026, the domain appears on one security blocklist, specifically PhishDestroy, confirming detection by at least one commercial threat feed. No additional brand target or scam kit details are currently available, and the exact content of the site remains unanalysed. VirusTotal scans conducted by 91 vendors returned no detections; however, the absence of flags does not confirm safety and may reflect a lack of prior exposure or evasion techniques. The domain remains operational, and infrastructure analysis reveals no indications of takedown or suspension. Registrar and hosting patterns align with known phishing infrastructure, though no direct attribution to a specific threat actor or campaign is established. Defenders are advised to treat defiswap-dex.com as a confirmed phishing domain targeting cryptocurrency users. Blocking the domain, associated IP, and nameservers at the network level is recommended. Security teams should monitor for connections to 186.2.175.109 and correlate with internal logs for potential compromise. Further investigation into the site’s functionality and payload delivery is ongoing, and updates will be provided as new evidence emerges. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260728-1501D3 Favicon MD5: 47b9f3dbb37297a7c8f6e3fdf5e66672 TLS cert SHA-256: 0b65c33ae09d2c9ff55da4916c17e0bce450aac4084986c01d129a3bb4e17098 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/defiswap-dex.com/ JSON API: https://api.destroy.tools/v1/check?domain=defiswap-dex.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,498 domains (83,265 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io