jupiter-swap-app-downlod[.]typedream[.]app
“Jupiter Swap: The Ultimate DEX Aggregator on Solana”
jupiter-swap-app-downlod.typedream.app — Contenido no disponible. Suplantación de marca: Jupiter; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 1/91 (LevelBlue); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrador: Typedream.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, jupiter-swap-app-downlod.typedream.app, was observed serving a page with the title “Jupiter Swap: The Ultimate DEX Aggregator on Solana.” The page title explicitly references the Jupiter brand, matching the reported brand‑impersonation classification. DNS resolution returned the IPv4 address 188.114.97.3, which belongs to ASN 13335 operated by Cloudflare, Inc., and is geolocated in the United States. No authoritative name servers were discovered, and the HTTP response code returned 404, indicating that the resource is no longer available. The site presented a valid TLS certificate issued by Google Trust Services under the subject “WE1,” confirming that HTTPS was correctly negotiated at the time of capture.
VirusTotal recorded a single positive detection out of ninety‑one scanned scanners, confirming that at least one security vendor identified malicious characteristics. Independent blocklist feeds list the domain on three separate repositories, and the domain is explicitly blocked by PhishDestroy, MetaMask, and SEAL, reinforcing the consensus that it constitutes a brand‑impersonation threat. The registrar information shows that the domain was created through Typedream, a website‑building service, which is frequently abused for fast‑deployment of fraudulent pages. Gridinsoft’s proprietary trust scoring assigned a rating of zero out of one hundred, reflecting an extremely low reputation.
The combination of a brand‑specific page title, a Cloudflare‑hosted IP, a single VirusTotal flag, multiple blocklist entries, and a zero trust score collectively indicate a high likelihood that the domain was used to deceive users seeking legitimate Jupiter services. Uncertainty remains regarding the specific payload or credential‑harvesting mechanism, as the page content could not be retrieved due to the 404 response and the domain’s offline status. Defenders should continue to block the domain at perimeter and endpoint filters, add the IP address 188.114.97.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Análisis de la configuración del sitio
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.