Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is domainabuse@tucows.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
hermeswalletswiss[.]com
Analyse phishing et sécurité de hermeswalletswiss.com
“Hermes Wallet Swiss | Neo Crypto Banking & Crypto Payment Infrastructure”
hermeswalletswiss.com — Dernier actif connu (HTTP 200). Type d'arnaque : Crypto Drainer. Résumé des preuves: VirusTotal 6/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); URLQuery 1 alert; Spamhaus DBL_SPAM; PhishDestroy score 82/100. Bureau d’enregistrement: TUCOWS.COM, CO.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, hermeswalletswiss.com, is identified as an active crypto drainer impersonating the Hermes wallet brand. Current intelligence confirms the threat is ongoing and under investigation by security teams. The infrastructure is actively resolving malicious activities targeting cryptocurrency users.
Analysis indicates the domain was registered on April 1, 2026, through TUCOWS.COM, CO. It resolves to the IP address 209.99.191.182, which has not been widely flagged at this time. VirusTotal currently reports 0 detections out of 95 vendor engines queried, suggesting this domain is not yet widely recognized as malicious. The newly registered domain status and lack of detections contribute to its elevated risk profile, as threat actors often exploit such blind spots to evade early detection mechanisms.
Given the domain's active status and its apparent role in draining cryptocurrency wallets under the guise of a legitimate service, immediate defensive actions are recommended. Security teams should block both the domain hermeswalletswiss.com and its resolved IP address 209.99.191.182 at the network perimeter. Additionally, endpoint monitoring should be enhanced to detect potential interactions with this domain, such as HTTP requests or DNS resolutions. Given its recent creation and low detection rate, proactively updating threat intelligence feeds with this indicator is critical to prevent further compromise.
Renseignements sur la sécurité réseau
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | hermeswalletswiss.com |
malicious | Sinkholed |
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 4 identified
Windows Server is a brand name for a group of server operating systems.
microsoft.com Confiance à 100 %ASP.NET is an open-source, server-side web-application framework designed for web development to produce dynamic web pages.
www.asp.net Confiance à 100 %Internet Information Services (IIS) is an extensible web server software created by Microsoft for use with the Windows NT family.
www.iis.net Confiance à 100 %HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confiance à 100 %Analyse VirusTotal
Données factuelles et rapports externes
PD-20260625-B5A0CE Recipient: domainabuse@tucows.com Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif