sign-sushi[.]lat
sign-sushi.lat — Contenuto non disponibile (HTTP 502). Simulazione del marchio: SushiSwap; Tipo di truffa: Crypto Scam. Riepilogo delle prove: VirusTotal 1/95 (Gridinsoft); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 74/100.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Analysis of sign-sushi.lat, created on February 21, 2026, shows that the domain is currently taken offline but retains several indicators of malicious intent. The domain resolves to IP address 104.21.112.1, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. An SSL certificate identified as WE1 is present, suggesting that the site employed HTTPS encryption despite its brief operational window. The page title returned by the server is "Just a moment...," a generic placeholder often used in malicious redirection chains, and no further content has been publicly captured.
The domain explicitly impersonates SushiSwap, a well‑known decentralized exchange, and is classified as a crypto‑related scam. VirusTotal reports a single detection out of 95 security vendors, indicating at least one scanner flagged the site as suspicious. Additionally, the domain appears on four independent blocklists—PhishDestroy, Polkadot, Enkrypt, and Codeesura—reinforcing the consensus that it is associated with illicit activity. No public Safe Browsing entry, OTX pulse, or additional intelligence has been disclosed, leaving the full extent of the threat unknown.
Given the concrete evidence—Cloudflare hosting, SSL presence, deceptive page title, confirmed brand impersonation, and inclusion on multiple blocklists—defenders should treat sign-sushi.lat as a high‑confidence malicious indicator. Recommended actions include adding the domain and its resolving IP to network‑level deny lists, updating endpoint protection signatures to flag any future resolution attempts, and monitoring for any resurrection of the domain or related subdomains. Continuous observation of Cloudflare‑hosted assets linked to the IP may reveal subsequent campaigns that reuse the same infrastructure. Until the domain remains offline, any traffic to sign-sushi.lat should be blocked to prevent potential crypto‑draining or credential‑theft attempts targeting SushiSwap users.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi di VirusTotal
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo