nvb-sushi[.]xyz
“403 Forbidden”
nvb-sushi.xyz — Conteúdo indisponível (HTTP 502). Representação da marca: SushiSwap; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 6/93 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet, Sophos); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 74/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain nvb-sushi.xyz was registered on February 21, 2026 and is currently classified as a brand impersonation campaign targeting SushiSwap. Infrastructure analysis shows the domain resolves to the IPv4 address 107.172.87.131, which is owned by AS36352 HostPapa and geolocated to the United States. An SSL certificate was observed on the host, identified as rating R10, but the site returns an HTTP 403 Forbidden response and the page title is reported as "403 Forbidden," indicating that the content is not publicly accessible at the time of analysis. The site is listed on four known security blocklists and has been actively blocked by PhishDestroy, Polkadot, Enkrypt, and Codeesura.
Reputation services assign a Gridinsoft trust score of 0 out of 100, reflecting a very low confidence in the domain's legitimacy. VirusTotal scans reveal that six of ninety-three security vendors flag the domain as malicious, providing additional corroboration of its abusive nature. The campaign’s declared scam type is a crypto scam, consistent with the impersonation of the SushiSwap brand.
Defenders should continue to block nvb-sushi.xyz at network and endpoint layers, monitor for any reactivation of the domain, and consider adding the associated IP address to deny lists. Because the site presently returns a 403 status and is offline, further content analysis is limited; however, the combination of registration timing, hosting details, low trust score, blocklist presence, and vendor detections strongly supports treating the domain as malicious. Ongoing vigilance is advised to detect any future resurrection of the infrastructure or related domains.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência forense
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo