MALICIOUS — CRITICAL
app[.]ssweep[.]cc
Analysis of the domain app.ssweep.cc shows it is currently active and resolves to the IPv4 address 188.114.97.3.
- VirusTotal
- 4/91
- Blocklists
- No stored match
- Disponibilità
- Contenuto non disponibile · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
app.ssweep.cc — Contenuto non disponibile (HTTP 502). Riepilogo delle prove: VirusTotal 4/91 (CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); PhishDestroy score 71/100. Registrar: Global Domain Group.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
app.ssweep.cc Phishing Site Detected
Analysis of the domain app.ssweep.cc shows it is currently active and resolves to the IPv4 address 188.114.97.3.
Analysis of the domain app.ssweep.cc shows it is currently active and resolves to the IPv4 address 188.114.97.3. The registration record indicates the domain was created on June 19, 2026 and is listed under the registrar Global Domain Group LLC. Authoritative name servers for the zone are patrick.ns.cloudflare.com and suzanne.ns.cloudflare.com, confirming the use of Cloudflare’s DNS infrastructure. The domain appears on a single security blocklist and is explicitly blocked by the PhishDestroy service, which classifies it as a generic phishing resource.
VirusTotal has processed the domain with scans from 95 vendors; none of the vendors have raised a detection, but the absence of a flag does not constitute evidence of benign intent. No public page title, brand target, or content snapshot is available in the current intelligence, leaving the exact phishing lure undefined. The combination of a newly registered domain, Cloudflare name servers, and inclusion on a known phishing blocklist suggests a deliberate attempt to exploit short‑lived infrastructure.
Defenders should add app.ssweep.cc to DNS and URL filtering rules, monitor traffic to the IP 188.114.97.3 for anomalous patterns, and consider sharing the indicator with additional blocklist providers. Continuous re‑evaluation is advised, as future content analysis may reveal the specific brand or credential‑harvesting technique employed.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 6 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org Confidenza al 100%Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org Confidenza al 100%Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of app.ssweep.cc · checked Jul 22, 2026
Dati e relazioni esterneIndependent lookups and source reports
“On 8 July 2026 (UTC), I signed transaction: Transaction Signature: 4Zzgy3v6kgWudcHM4H3e8ba6x6VaH4VjJnU2aPj9KLBow9c6Q4Rnisx12oWpkzsjsyQX8vY9ZWpVUnUpR43iyWHB After execution, the transaction invoked the following executable Solana program: 3wRre6bqgqBFfNUbdTaUGQSJ4vWFnbwe6QiWJgqzHiu7 According to the transaction records, this program executed the instructions that transferred 9.488166 USDC and 0.005095679 SOL from my wallet. Public blockchain records identify the program as: Executable Upgra”
PD-20260722-5E0183 Recipient: abuse@globaldomaingroup.com Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.