swap1inch[.]com
Resumo das evidências
Analysis of swap1inch.com indicates that the domain is being used for a brand‑impersonation crypto scam targeting users of the 1inch platform. The domain was registered on February 21, 2026 and is currently taken offline, suggesting that the operators have ceased active hosting or have removed the content. Network resolution points to the IP address 104.21.32.1, which is owned by Cloudflare, Inc. (AS13335) and is located in the United States. The SSL certificate presented for the site is labeled WE1, a generic certificate that does not provide any additional trust signals.
Threat intelligence feeds have listed the domain on four independent blocklists—PhishDestroy, Polkadot, Enkrypt, and Codeesura—demonstrating consensus among security vendors that the domain is malicious. A VirusTotal scan shows that five out of ninety‑three security vendors flagged the domain, reinforcing the blocklist findings. The domain’s branding is explicitly tied to the 1inch brand, as indicated by the brand target field, confirming a targeted impersonation attempt.
While the offline status limits immediate exposure, the historical presence on multiple blocklists and the positive VirusTotal detections suggest that the infrastructure was previously active and likely used to lure victims into a cryptocurrency‑related fraud. Defenders should continue to block swap1inch.com at network perimeters, update intrusion‑prevention signatures, and monitor for any re‑hosting attempts that may use the same IP or certificate fingerprint. Analysts should also watch for new domains that reuse the WE1 certificate or resolve to the same Cloudflare IP range, as these could represent a continuation of the campaign.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
7 fontes externas monitoradas Sem correspondência
Denúncias da comunidade
Denunciado por 1 membro da comunidade; visto pela primeira vez em 23/08/2025
- Denúncias armazenadas
- 1
- URLs únicas denunciadas
- 1
Inteligência da comunidade
1 denúncia da comunidade
CategoriaPHISHING
The PhishFort Detection System has flagged this as a domain threat, classified as phishing. Threat detected at 2025-08-18T13:00:28.614Z.
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
Inteligência forense
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo