v3-thorswap[.]xyz
“THORSwap”
v3-thorswap.xyz — Contenuto non disponibile (HTTP 502). Simulazione del marchio: 1inch; Tipo di truffa: Crypto Scam. Riepilogo delle prove: VirusTotal 3/93 (alphaMountain.ai, Forcepoint ThreatSeeker, Seclookup); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 74/100.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
The domain v3-thorswap.xyz was registered on 21 February 2026 and is presently taken offline. Infrastructure analysis shows that the hostname resolves to the IPv4 address 163.61.188.2, which is announced by ASN 153568 (NEW DHAKA HARDWARE) and geolocated to the United States. The site presented a TLS certificate identified as R10, indicating a short‑lived or self‑signed certificate. The HTTP response header reported a page title of “THORSwap”, which does not match the advertised brand.
Threat intelligence attributes the campaign to a brand‑impersonation effort targeting the cryptocurrency aggregator 1inch, classifying the activity as a crypto‑scam. The domain appears on four independent security blocklists, specifically PhishDestroy, Polkadot, Enkrypt, and Codeesura. VirusTotal analysis recorded three positive detections out of ninety‑three scanning engines, confirming malicious intent. The risk assessment is elevated, reflecting both the targeted brand and the observed malicious infrastructure.
Uncertainty remains regarding the exact payload delivered, the command‑and‑control infrastructure, and whether the domain was actively serving phishing pages before its takedown. Defenders should immediately block the IP address 163.61.188.2 and the domain v3-thorswap.xyz at perimeter and DNS layers, update detection signatures to include the observed TLS fingerprint and page title, and monitor for any re‑registration attempts under the same second‑level domain. Continuous observation of the listed blocklists and periodic re‑scanning on VirusTotal are recommended to capture potential re‑activation.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi di VirusTotal
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo