# PhishDestroy threat dossier — swoop2.me ================================================================ Fetched: 2026-07-31 09:00:10 UTC Canonical: https://phishdestroy.io/domain/swoop2.me/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Fortinet, Gridinsoft, SOCRadar, Sophos AlienVault OTX: 4 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 104.21.84.47 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Page title: DYNCUT: DDNS,Short URL, and text that is to the point HTTP response: 301 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-10-11 Status: INVALID chain Fingerprint: 80682049476522ee09ebb5c55fd13fcfa011d750669440481592bdf86d2036cd ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-28 14:43:09 UTC (by PhishDestroy tracker) Last verified: 2026-07-31 08:20:22 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-28 14:44:42 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is swoop2.me a Phishing Site? The domain swoop2.me is currently classified as a high‑risk generic phishing site. Analysis of open‑source intelligence shows that the domain is actively serving content and returns an HTTP 301 status code, suggesting it redirects visitors to a secondary location that may host the phishing payload. It has been added to at least one security blocklist and is explicitly blocked by the PhishDestroy service, indicating that defensive platforms have observed malicious activity associated with the domain. VirusTotal reports that four of ninety‑one scanning engines have flagged the domain, providing additional corroboration of its malicious nature. The domain remains active as of the report date, July 28, 2026, and no further detail on its hosting infrastructure, SSL certificate, registrar, or page title is publicly available. Consequently, the precise hosting location, certificate usage, and target brand or service cannot be confirmed at this time. Defenders should treat swoop2.me as hostile: block the domain at perimeter firewalls, proxy filters, and endpoint protection solutions; add it to internal blacklists; and monitor DNS logs for any resolution attempts. Continuous re‑evaluation is advised, as additional detections or changes in the domain’s infrastructure may emerge. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: 80682049476522ee09ebb5c55fd13fcfa011d750669440481592bdf86d2036cd ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/swoop2.me/ JSON API: https://api.destroy.tools/v1/check?domain=swoop2.me Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,251 domains (84,237 alive under monitoring, 27,268 confirmed neutralized). Site: https://phishdestroy.io