v3-thorswap[.]xyz
“THORSwap”
v3-thorswap.xyz — Konten tidak tersedia (HTTP 502). Peniruan identitas merek: 1inch; Jenis penipuan: Crypto Scam. Ringkasan bukti: VirusTotal 3/93 (alphaMountain.ai, Forcepoint ThreatSeeker, Seclookup); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 74/100.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
The domain v3-thorswap.xyz was registered on 21 February 2026 and is presently taken offline. Infrastructure analysis shows that the hostname resolves to the IPv4 address 163.61.188.2, which is announced by ASN 153568 (NEW DHAKA HARDWARE) and geolocated to the United States. The site presented a TLS certificate identified as R10, indicating a short‑lived or self‑signed certificate. The HTTP response header reported a page title of “THORSwap”, which does not match the advertised brand.
Threat intelligence attributes the campaign to a brand‑impersonation effort targeting the cryptocurrency aggregator 1inch, classifying the activity as a crypto‑scam. The domain appears on four independent security blocklists, specifically PhishDestroy, Polkadot, Enkrypt, and Codeesura. VirusTotal analysis recorded three positive detections out of ninety‑three scanning engines, confirming malicious intent. The risk assessment is elevated, reflecting both the targeted brand and the observed malicious infrastructure.
Uncertainty remains regarding the exact payload delivered, the command‑and‑control infrastructure, and whether the domain was actively serving phishing pages before its takedown. Defenders should immediately block the IP address 163.61.188.2 and the domain v3-thorswap.xyz at perimeter and DNS layers, update detection signatures to include the observed TLS fingerprint and page title, and monitor for any re‑registration attempts under the same second‑level domain. Continuous observation of the listed blocklists and periodic re‑scanning on VirusTotal are recommended to capture potential re‑activation.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive