app-s1[.]eu[.]com
“KittenSwap Treats - Delightful Dining Experience”
Riepilogo delle prove
On July 24, 2026 analysts observed that the domain app-s1.eu.com is currently offline but exhibits multiple indicators consistent with a brand‑impersonation campaign targeting Revolut. The domain was registered on February 21, 2026 through Instra Corporation Pty Ltd. and is hosted on Cloudflare infrastructure (AS13335) with the IPv6 address 2606:4700:3030::6815:5acd, which resolves to a United States location. DNS configuration shows four centralnic.net name servers (ns1‑ns4.centralnic.net) and an MX record pointing to eu-com-wildcard-null-mx.centralnic.net with priority 0, suggesting the domain is prepared to receive email traffic despite its offline HTTP status. The site’s page title, as captured before takedown, reads "KittenSwap Treats - Delightful Dining Experience," a title unrelated to Revolut and indicative of content spoofing.
The domain appears on a single security blocklist and has been explicitly blocked by PhishDestroy, confirming that defensive feeds have identified it as malicious. VirusTotal analysis recorded detections from 2 of 93 security vendors, reinforcing the suspicion of abuse. The SSL certificate is labeled as type E6, but no further validation details are available. While the HTTP service is currently unavailable, the presence of a valid SSL certificate and active MX record imply that the infrastructure could be re‑activated.
Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any resurrection of the web service, and watch for related email phishing attempts using the listed MX host. Additional investigation should focus on any payloads or credential‑stealing pages that may have been hosted previously, and on correlating the IPv6 address with other known Cloudflare‑hosted abuse. The combination of brand impersonation, blocklist inclusion, and vendor detections warrants an elevated risk rating and proactive mitigation.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Segnalazioni della comunità
Segnalato da 1 membro della comunità; prima osservazione il 10/07/2025
- Segnalazioni memorizzate
- 1
- URL segnalati univoci
- 1
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo