gho-swap[.]com
“GHO Swap â #1 EVM DEX | Precision Swap, Pool, Stake & Airdrop”
gho-swap.com — असत्यापित. ब्रांड प्रतिरूपण: Aave; घोटाले का प्रकार: Crypto Drainer. साक्ष्य सारांश: VirusTotal 4/91 (alphaMountain.ai, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); 1 external blocklist match (ScamSniffer); PhishDestroy score 65/100. रजिस्ट्रार: Fewmoretaps OU d/b/a T….
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Analysis of gho-swap.com indicates a newly registered domain created on July 31, 2026 and currently active. The registrar entry shows the domain was registered through Fewmoretaps OU d/b/a Trustname.com, suggesting a potential use of a legitimate‑sounding business name to obscure ownership. DNS resolution points to the IP address 188.114.96.3, hosted on Cloudflare infrastructure as evidenced by the authoritative nameservers elijah.ns.cloudflare.com and teagan.ns.cloudflare.com.
The domain appears on a single security blocklist and is explicitly blocked by PhishDestroy, reinforcing the hypothesis that it is being used for malicious purposes. VirusTotal has recorded scans from 91 vendors; while no vendor flagged the domain at the time of scanning, the absence of detections does not constitute a safety assurance and should be interpreted as an indicator that the site has not yet triggered automated signatures. No additional public intelligence such as Safe Browsing verdicts, OTX mentions, SSL certificate details, HTTP response codes, or page title information is available, leaving many operational characteristics of the site unknown.
Defenders should therefore treat the domain as high‑risk until further evidence clarifies its behavior. Recommended mitigations include adding explicit block rules for the IP 188.114.96.3 and the domain name in network firewalls and web proxies, monitoring DNS queries for the Cloudflare nameservers, and maintaining up‑to‑date threat feeds that reference the PhishDestroy block. Continuous re‑scanning with multi‑vendor sandbox services is advised to capture any changes in payload or hosting, and any observed credential or payment data exfiltration attempts should be investigated as potential indicators of compromise linked to this infrastructure.
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% विश्वासCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% विश्वासHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% विश्वासवायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of gho-swap.com · checked Aug 5, 2026
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।