# PhishDestroy threat dossier — hermeswalletswiss.com ================================================================ Fetched: 2026-07-22 11:18:45 UTC Canonical: https://phishdestroy.io/domain/hermeswalletswiss.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 93/100 (PhishDestroy scoring — see methodology below) Scam classification: Crypto Drainer ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: Fortinet, SOCRadar URLQuery: 2 detections Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 209.99.191.182 (CH, Zürich) ASN: ASAS402253 SKN-NETWORK-1 - SKN Subnet & Telecom Ltd, KN Hosting org: AS402253 SKN Subnet & Telecom Ltd Registrar: TUCOWS.COM, CO. Nameservers: 1-you.njalla.no, 2-can.njalla.in, 3-get.njalla.fo Registered: 2026-04-01 Expires: 2027-04-01 Page title: Hermes Wallet Swiss | Neo Crypto Banking & Crypto Payment Infrastructure HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-08-10 Status: INVALID chain Fingerprint: 5f89dd6a2755ec5d8357c77fe719d50756c4fe39be05abe11deccb2fc6fb7011 Subject Alternative Names (related infrastructure — often same operator): - chat.hermeswalletswiss.com - www.hermeswalletswiss.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-01 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-25 02:54:59 UTC (by PhishDestroy tracker) First reported: 2026-06-25 01:01:50 UTC (abuse notice filed) Last verified: 2026-07-22 12:20:38 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019efc44-f4af-733c-985d-dee35ef5545d/ URLQuery: https://urlquery.net/report/5dc28095-4ba2-46f0-b302-e3efdc768873 Wayback Machine: https://web.archive.org/web/*/hermeswalletswiss.com crt.sh CT logs: https://crt.sh/?q=%25.hermeswalletswiss.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=hermeswalletswiss.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/hermeswalletswiss.com URLhaus: https://urlhaus.abuse.ch/host/hermeswalletswiss.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-25 03:00:07 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] hermeswalletswiss.com Fake Hermes Wallet Alert – Crypto Drainer This domain, hermeswalletswiss.com, is identified as an active crypto drainer impersonating the Hermes wallet brand. Current intelligence confirms the threat is ongoing and under investigation by security teams. The infrastructure is actively resolving malicious activities targeting cryptocurrency users. Analysis indicates the domain was registered on April 1, 2026, through TUCOWS.COM, CO. It resolves to the IP address 209.99.191.182, which has not been widely flagged at this time. VirusTotal currently reports 0 detections out of 95 vendor engines queried, suggesting this domain is not yet widely recognized as malicious. The newly registered domain status and lack of detections contribute to its elevated risk profile, as threat actors often exploit such blind spots to evade early detection mechanisms. Given the domain's active status and its apparent role in draining cryptocurrency wallets under the guise of a legitimate service, immediate defensive actions are recommended. Security teams should block both the domain hermeswalletswiss.com and its resolved IP address 209.99.191.182 at the network perimeter. Additionally, endpoint monitoring should be enhanced to detect potential interactions with this domain, such as HTTP requests or DNS resolutions. Given its recent creation and low detection rate, proactively updating threat intelligence feeds with this indicator is critical to prevent further compromise. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260625-B5A0CE Favicon MD5: d214ba80dae7b0efdb4e18fc3de85183 TLS cert SHA-256: 5f89dd6a2755ec5d8357c77fe719d50756c4fe39be05abe11deccb2fc6fb7011 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/hermeswalletswiss.com/ JSON API: https://api.destroy.tools/v1/check?domain=hermeswalletswiss.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,008 domains (57,476 alive under monitoring, 128,899 confirmed takedowns/dead). Site: https://phishdestroy.io