# PhishDestroy threat dossier — swiftfidelitymarket.org ================================================================ Fetched: 2026-07-29 17:52:43 UTC Canonical: https://phishdestroy.io/domain/swiftfidelitymarket.org/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Gridinsoft, SOCRadar AlienVault OTX: 3 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 51.68.132.244 (PL, Warsaw) ASN: AS16276 OVH SAS Hosting org: Limited - PVT Hostseo Registrar: OrangeHost LLC Nameservers: ns1.jedacprohost.com, ns2.jedacprohost.com Registered: 2026-01-14 Expires: 2027-01-14 Page title: swiftfidelitymarket HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-11 Status: INVALID chain Fingerprint: 61ea833401bd8c3de49e29b43323fb6cb63d4821ee57210e91177c993b21c19a ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-01-14 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 08:25:54 UTC (by PhishDestroy tracker) First reported: 2026-07-27 09:35:12 UTC (abuse notice filed) Last verified: 2026-07-29 16:20:25 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa24f-994d-7472-b155-976d557425c3/ URLQuery: https://urlquery.net/report/d9c55d1e-be8c-4583-90cc-4c7a56ddb1ad Wayback Machine: https://web.archive.org/web/*/swiftfidelitymarket.org crt.sh CT logs: https://crt.sh/?q=%25.swiftfidelitymarket.org Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=swiftfidelitymarket.org AlienVault OTX: https://otx.alienvault.com/indicator/domain/swiftfidelitymarket.org URLhaus: https://urlhaus.abuse.ch/host/swiftfidelitymarket.org/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 08:29:23 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] swiftfidelitymarket.org — Generic Phishing This domain was flagged on July 27, 2026 as a generic phishing site. swiftfidelitymarket.org is hosted on the IP address 51.68.132.244 and uses the authoritative name servers ns1.jedacprohost.com and ns2.jedacprohost.com. The domain was registered on January 14, 2026 through OrangeHost LLC, a registrar that is frequently used for short‑lived malicious infrastructure. The registration date indicates a recent creation, consistent with the rapid turnover typical of phishing campaigns. The IP belongs to a hosting provider that does not publish a public abuse contact, and no SSL certificate details are available in the current intelligence set. VirusTotal reports that the domain has been scanned by 91 anti‑malware vendors; none reported a detection at the time of analysis, but the absence of a detection does not constitute a safety guarantee. The domain appears on a single security blocklist and has been added to the PhishDestroy blocklist, confirming that at least one external sinkhole has identified it as malicious. No additional public blocklists or Safe Browsing entries are recorded. No Open Threat Exchange (OTX) pulse or similar indicator is currently linked to the domain. Because the page title, HTTP response code, and any observed content have not been captured, the exact phishing vector remains unknown. Defenders should continue to block traffic to 51.68.132.244 and to swiftfidelitymarket.org at the network perimeter, monitor DNS queries for the associated name servers, and add the domain to internal URL filtering policies. Continuous re‑scanning with updated vendor engines is advised, as the lack of detections may change if the payload evolves. Incident response teams should treat any credential submissions to this domain as compromised and advise affected users to reset passwords immediately. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-3E04BE Favicon MD5: 39d5d70fbacf261e4f59770e1b7be9cc TLS cert SHA-256: 61ea833401bd8c3de49e29b43323fb6cb63d4821ee57210e91177c993b21c19a ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/swiftfidelitymarket.org/ JSON API: https://api.destroy.tools/v1/check?domain=swiftfidelitymarket.org Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,499 domains (83,266 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io