Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@nicenic.net.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
houdiniswpa[.]com
“Houdini Swap | Swap Bitcoin Privately or any Crypto Anonymously”
houdiniswpa.com — Encoberto · alcançável. Representação da marca: Bitcoin; Tipo de golpe: Generic Phishing. Resumo das evidências: VirusTotal 10/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, ESET); Spamhaus DBL_PHISH; cloaking observed; PhishDestroy score 100/100. Registrador: NiceNIC.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies houdiniswpa.com as an active cryptocurrency drainer kit impersonating legitimate services to steal digital assets. The domain is designed to deceive users into connecting wallets or entering credentials, enabling unauthorized fund transfers. No specific brand is mimicked in available intelligence, suggesting a generalized but targeted approach to crypto users seeking anonymity or magic-related services under the 'houdini' moniker. The site employs deceptive frontend elements to mask its malicious intent, typical of modern drainer kits that automate wallet draining post-authentication. The infrastructure is deliberately modern, leveraging trusted SSL certificates to appear legitimate at first glance, a tactic increasingly common in cryptocurrency-targeted phishing campaigns.
Technical analysis reveals several critical indicators: VirusTotal detection stands at 1/95 security vendors (as of the latest scan), indicating low but present visibility among security tools. The domain resolves to IP 172.67.190.219, hosted on Cloudflare infrastructure, which is frequently abused for phishing due to its legitimate traffic obfuscation capabilities. Registration occurred on October 11, 2025, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar known for bulk domain registrations that often correlate with malicious activity. The SSL certificate, issued by Google Trust Services, adds a veneer of authenticity, though its recent issuance aligns with the domain’s creation date. No public blocklist entries are currently recorded for this domain, underscoring the importance of proactive threat hunting.
The site remains active as of the latest assessment, with threat actors likely iterating on the drainer kit to evade detection. Immediate response actions include domain takedown requests to the registrar and hosting provider, alongside updating network defenses to block the IP and domain at the firewall and DNS levels. Users are advised to verify site legitimacy via official channels, avoid clicking unsolicited links, and employ hardware wallet solutions or transaction simulation tools to detect drainer script injections. Remaining risk is elevated due to the domain’s recent activation and the absence of widespread blocklisting, necessitating vigilance from cryptocurrency holders and security teams alike.
Inteligência de segurança de rede Registrar context
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-16 02:42:20 UTC
Inteligência forense
Análise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of houdiniswpa.com · checked Apr 8, 2026
Evidências e relatórios externos
PD-20260408-A54980 Recipient: abuse@nicenic.net Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo