swapspace[.]exchange
“SwapSpace — Instant Crypto Exchange Without KYC or Registration”
Résumé des preuves
Analysis of swapspace.exchange indicates a high‑risk brand‑impersonation campaign targeting users of the Aave platform. The domain was registered on August 11, 2025 through NICENIC INTERNATIONAL GROUP CO., LIMITED and resolves to the IP address 104.21.80.1, which belongs to AS13335 Cloudflare, Inc. in the United States. No SSL certificate was observed, suggesting the site operated over plain HTTP. The hosted page title – “SwapSpace — Instant Crypto Exchange Without KYC or Registration” – aligns with the declared scam type of a crypto scam and does not reference Aave directly, yet the domain is flagged for impersonating the Aave brand.
Reputation data shows a Gridinsoft trust score of 0 out of 100, confirming a lack of legitimacy. The domain appears on four security blocklists (PhishDestroy, Polkadot, Enkrypt, and Codeesura) and has been flagged by 13 of 95 vendors on VirusTotal, reinforcing its malicious nature. Current status is offline, but historical evidence suggests it was previously active and served malicious content.
Defenders should block the domain at network perimeters, update DNS filtering rules, and monitor for any residual traffic to the associated Cloudflare IP. Additional investigation of related sub‑domains or similar registrations by the same registrar may uncover further infrastructure. Because the site is no longer reachable, remediation focuses on preventive controls and threat‑intel sharing to mitigate future impersonation attempts against Aave users.
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 10/08/2026
7 sources externes surveillées Aucune correspondance
Preuves du résultat enregistrées
Résultat et attribution du retrait
- Résultat
held- Disponibilité
unreachable- Cause
registrar_client_hold- Acteur
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- Mécanisme
client_hold- Confiance
- 95%
- Première observation
- Dernière observation
Indisponibilité estimée
Délai avant indisponibilité: 0 hSHA-256 de la preuve 01be9a32cc69
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
Disponibilité
Première valeur enregistrée : DNS inactif
f93a11f87e4d -
Disponibilité
DNS inactif → Inconnu
2464aff21e3f -
Disponibilité
Inconnu → Retenu
82cdeb79beac -
Disponibilité
Retenu → Inactif
db53dc740b82 -
Disponibilité
Inactif → DNS inactif
10d712618407 -
Disponibilité
DNS inactif → Inconnu
95b76105ccf1 -
Disponibilité
Inconnu → Retenu
51dbe6586565 -
Disponibilité
Retenu → Inconnu
27bf043e333e -
Disponibilité
Inconnu → DNS inactif
6dfe9145995c
Tout afficher (7)
-
Disponibilité
DNS inactif → Retenu
5a1fc956d563 -
Disponibilité
Retenu → DNS inactif
641ed81dc4d5 -
Disponibilité
DNS inactif → Inconnu
6ba45a1271c4 -
Disponibilité
Inconnu → Retenu
7da695769f9a -
Disponibilité
Retenu → Inconnu
0ecc9df6a5eb -
Disponibilité
Inconnu → DNS inactif
d0b7046e8c2f -
Disponibilité
DNS inactif → Retenu
01be9a32cc69
Signalements communautaires
Signalé par 1 membre de la communauté ; première observation le 16/08/2025
- Signalements enregistrés
- 1
- URL signalées uniques
- 1
Renseignement communautaire
1 signalement communautaire
CatégoriePHISHING
Detection Summary The Anti-Phishing Volunteers & Associates Security Incident Response System has flagged this as a domain threat, classified as phishing attack against several brands. Threat detected at 2025-11-19T02:42:17.415Z. Targeted Brands Atomic Wallet Uniswap SwapSpace Pa
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Preuves archivées
Domaines ressemblants
95 domaines ressemblants enregistrés
Tout afficher (83)
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif