# PhishDestroy threat dossier — simpleswap.capital ================================================================ Fetched: 2026-07-25 20:22:21 UTC Canonical: https://phishdestroy.io/domain/simpleswap.capital/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Fake Exchange ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 3/91 security vendors flagged this domain Flagging vendors: BitDefender, Fortinet, G-Data Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 91.92.241.159 (NL, Amsterdam) ASN: ASAS202412 OMEGATECH-AS Omegatech LTD, SC Hosting org: AS202412 Omegatech LTD Registrar: Hosting Concepts B.V. d/b/a Registrar.eu Nameservers: ns1.metaquotes.business, ns2.metaquotes.business Registered: 2026-07-03 Expires: 2027-07-03 Page title: Simple swap HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: ZeroSSL GmbH / ZeroSSL ECC DV SSL CA 2 Expires: 2026-10-22 Status: INVALID chain Fingerprint: a44f03cdfc84c0b970aa51ae85ab2232f6485623eedcdc4a9f3709450a81b77c ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-03 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-25 06:55:35 UTC (by PhishDestroy tracker) First reported: 2026-07-25 05:00:02 UTC (abuse notice filed) Last verified: 2026-07-25 20:20:20 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f97a8-c29d-7308-a1c5-e9e65c2d0b91/ URLQuery: https://urlquery.net/report/8a11ecbf-6fee-4cb6-abef-d6d284ae0c9e Wayback Machine: https://web.archive.org/web/*/simpleswap.capital crt.sh CT logs: https://crt.sh/?q=%25.simpleswap.capital Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=simpleswap.capital AlienVault OTX: https://otx.alienvault.com/indicator/domain/simpleswap.capital URLhaus: https://urlhaus.abuse.ch/host/simpleswap.capital/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-25 06:55:51 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is simpleswap.capital a Cryptocurrency Exchange Scam Site? Analysis indicates that simpleswap.capital is a recently registered domain exhibiting multiple high-risk indicators consistent with phishing activity targeting cryptocurrency users. The domain was created on July 03, 2026, through Hosting Concepts B.V. d/b/a Registrar.eu and remains active as of July 25, 2026. Infrastructure analysis reveals it resolves to the IP address 91.92.241.159, which has previously been associated with suspicious hosting environments. The domain is currently flagged by one security vendor, PhishDestroy, and is detected by 3 of 91 security vendors on VirusTotal, suggesting early but growing recognition of its malicious nature. Nameservers ns1.metaquotes.business and ns2.metaquotes.business further link the domain to infrastructure commonly used for financial scams, particularly those involving cryptocurrency or trading platforms. While the exact content of the site has not been fully analyzed, the domain name and detection patterns strongly suggest an attempt to impersonate a legitimate cryptocurrency exchange service. Defenders should treat this domain as high-risk and prioritize blocking or monitoring access to it. Network security teams are advised to review logs for connections to 91.92.241.159 and the associated nameservers, as well as to implement real-time blocking based on available threat intelligence feeds. No SSL certificate details or HTTP response data are currently available to confirm the site's operational status or content, but the combination of registration recency, hosting infrastructure, and early detection by security vendors warrants immediate caution. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260725-3A5437 Favicon MD5: 37dac657b394522a6175ba5aa00541ff TLS cert SHA-256: a44f03cdfc84c0b970aa51ae85ab2232f6485623eedcdc4a9f3709450a81b77c ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/simpleswap.capital/ JSON API: https://api.destroy.tools/v1/check?domain=simpleswap.capital Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 192,798 domains (62,984 alive under monitoring, 128,255 confirmed takedowns/dead). Site: https://phishdestroy.io