sushi-lnq[.]top
“Stake SUSHI | Sushi”
sushi-lnq.top — Conteúdo indisponível (HTTP 502). Representação da marca: SushiSwap; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 8/93 (alphaMountain.ai, BitDefender, CyRadar, Fortinet, G-Data); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 79/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain is flagged as an elevated-risk crypto drainer specifically targeting users of the decentralized exchange SushiSwap. Analysis indicates the infrastructure is designed to impersonate legitimate staking interfaces, tricking victims into connecting wallets and authorizing malicious transactions that siphon funds without consent. The threat type is classified as brand impersonation with embedded crypto-draining functionality, a common tactic in decentralized finance (DeFi) scams. Infrastructure analysis reveals the domain sushi-lnq.top was registered on February 21, 2026, and resolves to the IP address 107.172.83.150, hosted on AS36352 (HostPapa) in the United States. The SSL certificate is issued under the R11 root, a detail often associated with low-reputation or ephemeral hosting environments. The page title, 'Stake SUSHI | Sushi,' directly mimics SushiSwap’s branding, while the domain appears on four security blocklists, including PhishDestroy, Polkadot, Enkrypt, and Codeesura. VirusTotal detection rates show 8 out of 95 security vendors flagging the domain as malicious, with the current status marked as offline following takedown actions. Mitigation against this threat type requires heightened vigilance from DeFi users. Wallet connections should never be authorized on unfamiliar domains, even if the interface appears identical to legitimate platforms. Users are advised to verify domain authenticity through official project documentation or community channels before interacting with any staking or yield farming portal. Wallet software and browser extensions that block known malicious domains provide an additional layer of protection. In cases where interaction has already occurred, immediate revocation of all recent smart contract approvals is critical to prevent further unauthorized transactions. Organizations managing DeFi infrastructure should proactively monitor for newly registered domains containing their brand names and take swift action to disrupt impersonation attempts.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência forense
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo