usdt-exchange-swap[.]com
“USDT Exchange Swap – Anonymous Crypto Conversions Without KYC or Registration”
usdt-exchange-swap.com — 서버 오류 (HTTP 502). 브랜드 사칭: Aave; 사기 유형: Crypto Scam. 증거 요약: VirusTotal 4/93 (alphaMountain.ai, CyRadar, Fortinet, Webroot); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 79/100. 등록기관: NiceNIC.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
The domain usdt-exchange-swap.com was registered on February 21, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and resolves to IP address 104.21.84.191, which is owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. The site presented the page title "USDT Exchange Swap – Anonymous Crypto Conversions Without KYC or Registration," indicating a crypto‑exchange narrative that does not request user verification. The domain explicitly claims to impersonate the Aave brand, aligning with a known brand‑impersonation threat vector targeting cryptocurrency users. Trust metrics are extremely low, with Gridinsoft assigning a score of 0 out of 100 and Scamadviser a score of 1 out of 100, reflecting severe reputational risk.
The SSL certificate is identified as "WE1," but no further validation details are provided. Multiple security blocklists have flagged the domain; it appears on four independent blocklists and has been actively blocked by PhishDestroy, Polkadot, Enkrypt, and Codeesura. VirusTotal analysis shows that 4 of 93 scanning engines flagged the domain, reinforcing the malicious classification. As of the report date, July 24, 2026, the site is reported offline, which may be temporary or a takedown response.
However, the underlying infrastructure—Cloudflare hosting and the low‑trust registrar—remains controllable by the threat actor. Defenders should continue to monitor the IP address for any reactivation, enforce blocklist updates for the domain and its hosting network, and educate users about the Aave impersonation attempt, especially those seeking anonymous crypto conversions without KYC. Additional investigation of the SSL certificate and any residual DNS records is recommended to fully map the threat actor's infrastructure.
네트워크 보안 인텔리전스 Registrar context
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
ICANN OVERSIGHT
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-16 03:29:53 UTC
포렌식 인텔리전스
VirusTotal 분석
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.