jupiter-swap-app-downlod[.]typedream[.]app
“Jupiter Swap: The Ultimate DEX Aggregator on Solana”
jupiter-swap-app-downlod.typedream.app — Contenuto non disponibile. Simulazione del marchio: Jupiter; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 1/91 (LevelBlue); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrar: Typedream.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
This domain, jupiter-swap-app-downlod.typedream.app, was observed serving a page with the title “Jupiter Swap: The Ultimate DEX Aggregator on Solana.” The page title explicitly references the Jupiter brand, matching the reported brand‑impersonation classification. DNS resolution returned the IPv4 address 188.114.97.3, which belongs to ASN 13335 operated by Cloudflare, Inc., and is geolocated in the United States. No authoritative name servers were discovered, and the HTTP response code returned 404, indicating that the resource is no longer available. The site presented a valid TLS certificate issued by Google Trust Services under the subject “WE1,” confirming that HTTPS was correctly negotiated at the time of capture.
VirusTotal recorded a single positive detection out of ninety‑one scanned scanners, confirming that at least one security vendor identified malicious characteristics. Independent blocklist feeds list the domain on three separate repositories, and the domain is explicitly blocked by PhishDestroy, MetaMask, and SEAL, reinforcing the consensus that it constitutes a brand‑impersonation threat. The registrar information shows that the domain was created through Typedream, a website‑building service, which is frequently abused for fast‑deployment of fraudulent pages. Gridinsoft’s proprietary trust scoring assigned a rating of zero out of one hundred, reflecting an extremely low reputation.
The combination of a brand‑specific page title, a Cloudflare‑hosted IP, a single VirusTotal flag, multiple blocklist entries, and a zero trust score collectively indicate a high likelihood that the domain was used to deceive users seeking legitimate Jupiter services. Uncertainty remains regarding the specific payload or credential‑harvesting mechanism, as the page content could not be retrieved due to the 404 response and the domain’s offline status. Defenders should continue to block the domain at perimeter and endpoint filters, add the IP address 188.114.97.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi di VirusTotal
Analisi della configurazione del sito
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo