sushi-grt[.]top
“Stake SUSHI | Sushi”
sushi-grt.top — 콘텐츠를 사용할 수 없음 (HTTP 502). 브랜드 사칭: SushiSwap; 사기 유형: Crypto Scam. 증거 요약: VirusTotal 9/93 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, ESET); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 77/100.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
Analysis of sushi-grt.top indicates a brand-impersonation campaign targeting SushiSwap users. The domain was registered on 21 February 2026 and, as of the report date, is taken offline after being blocked by PhishDestroy, Polkadot, Enkrypt and Codeesura. DNS resolution points to 107.172.83.150, an address owned by AS36352 (HostPapa) located in the United States. The site presented an R11 SSL certificate, a standard TLS certificate without extended validation, which does not provide any additional trust. VirusTotal scans show nine of ninety‑three security vendors flagging the domain as malicious, reinforcing the suspicion of abuse.
Four security blocklists currently list the domain, and the same four blocklists are also reflected in the blocklist count. The page title returned from the HTTP response is "Stake SUSHI | Sushi", directly referencing the SushiSwap brand and confirming the declared impersonation intent. The scam type is identified as a crypto‑scam, consistent with the use of the Sushi token name in the title. No further content, login forms, or credential‑harvesting mechanisms have been publicly disclosed, leaving the exact payload and victim‑interaction flow uncertain.
The hosting provider HostPapa is a popular shared‑hosting service, which may host unrelated legitimate sites; therefore, remediation should focus on the specific domain and IP rather than broad provider blocking. Defenders should continue to block the domain at DNS and proxy layers, add the associated IP address to network‑level deny lists, and monitor for any new subdomains or similarly crafted domains that reference SushiSwap or the Sushi token. Updating detection signatures with the observed page title and SSL fingerprint can improve early identification of related campaigns. Continuous review of blocklist feeds and VirusTotal alerts is recommended to capture any re‑activation attempts.
위협 대응 Pipeline
공개 차단 목록 상태
VirusTotal 분석
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.