swap-coin[.]fun
“Обменный пункт электронных валют”
swap-coin.fun — सामग्री अनुपलब्ध (HTTP 502). ब्रांड प्रतिरूपण: Avalanche; घोटाले का प्रकार: Crypto Scam. साक्ष्य सारांश: VirusTotal 2/93 (Gridinsoft, SOCRadar); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 74/100. रजिस्ट्रार: Beget.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Analysis of swap-coin.fun, taken offline as of the report date 24 July 2026, shows an infrastructure deliberately crafted to impersonate the Avalanche brand in a crypto‑scam context. The domain was registered on 28 December 2025 through Beget LLC, a Russian‑based registrar that also provides the authoritative name servers ns1.beget.com, ns1.beget.pro, ns2.beget.com and ns2.beget.pro. DNS resolution points to IP address 45.130.41.125, which belongs to AS198610 owned by Beget LLC and is geolocated in Russia. No TLS certificate is presented, indicating the site operated over plain HTTP.
The sole visible artifact is the page title "Обменный пункт электронных валют," a Russian phrase meaning “electronic currency exchange point,” which aligns with the declared crypto‑scam classification. Security‑industry tooling has flagged the domain on four blocklists, and it has been actively blocked by PhishDestroy, Polkadot, Enkrypt and Codeesura. Gridinsoft assigns a trust score of 0 / 100, reflecting a complete lack of credibility. VirusTotal analysis records two detections out of ninety‑three scanners, confirming that at least a minority of AV engines recognize malicious behavior.
The elevated risk rating derives from the combination of brand impersonation, lack of encryption, and confirmed detections. Uncertainty remains regarding the exact payload or credential‑harvesting mechanisms, as no additional page content has been disclosed. Defenders should continue to enforce network‑level denial of 45.130.41.125, ensure the domain remains on blocklists, and monitor Beget’s name‑server zones for re‑registration attempts. Regular re‑scans with multi‑engine services are advised to capture any evolution of the payload, and incident response teams should treat any traffic to this host as hostile, given the confirmed brand‑spoofing intent.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।