fhe-sushi[.]cfd
Evidence Summary
The domain fhe-sushi.cfd is a phishing site engaged in brand impersonation targeting SushiSwap, a cryptocurrency exchange platform. It poses an elevated risk as a cryptocurrency scam designed to deceive users into disclosing sensitive information or transferring funds under false pretenses. No drainer kit was identified in this campaign. The site is currently taken offline, but prior activity indicates it was actively used for malicious purposes.
Technical indicators confirm the domain fhe-sushi.cfd was flagged by 1 of 95 VirusTotal security vendors, including Gridinsoft, which assigned a trust score of 0/100. The domain appears on 4 security blocklists, specifically PhishDestroy, Polkadot, Enkrypt, and Codeesura. It was created on February 21, 2026, and resolved to the IP address 172.67.144.169, hosted on Cloudflare's infrastructure (AS13335) in the US. The SSL certificate was issued by WE1, and the observed page title was 'Just a moment...'. No registrar information is available for this domain.
Users who interacted with fhe-sushi.cfd should immediately revoke any token approvals granted to unknown contracts and transfer remaining funds to a new, secure wallet. Enable two-factor authentication (2FA) on all cryptocurrency accounts and monitor for unauthorized transactions. Change passwords for any accounts accessed during the suspected phishing attempt. Report the domain to relevant platforms, including Google Safe Browsing, anti-phishing organizations, and the impersonated brand (SushiSwap) to aid in mitigation efforts.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
7 monitored external feeds No match
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
SHORTDOT ZONE · PUBLIC EVIDENCE
.cfd
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
Forensic Intelligence
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive