swift-oxygen-wide[.]on-fleek[.]app
“Special Member Giveaway”
swift-oxygen-wide.on-fleek.app — Não verificado. Tipo de golpe: Fake Giveaway. Resumo das evidências: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); 4 external blocklist matches; CF Radar malicious; PhishDestroy score 95/100. Registrador: 1API.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, swift-oxygen-wide.on-fleek.app, is flagged as an active phishing site targeting users through a fraudulent giveaway scheme. Analysis of the page title, "Special Member Giveaway," indicates an attempt to lure victims with false promises of rewards or exclusive offers. The domain is currently resolving to IP address 172.67.73.189, hosted on infrastructure belonging to Cloudflare, Inc. (AS13335), a common tactic to obscure the true origin of malicious activity. The site employs a Let's Encrypt SSL certificate, which while providing encryption, does not validate the legitimacy of the content being served. Infrastructure analysis reveals the domain is registered through 1API GmbH and utilizes Cloudflare nameservers, specifically rihana.ns.cloudflare.com and scott.ns.cloudflare.com. The HTTP status code 301 suggests a redirect mechanism may be in place, potentially rerouting victims to additional malicious endpoints. As of July 12, 2026, the domain appears on five security blocklists and is flagged by 12 out of 95 security vendors in VirusTotal, confirming its classification as high-risk. The exact nature of the phishing kit or the specific brand being impersonated remains unconfirmed, as no additional technical indicators beyond the page title are currently available. Defenders should treat this domain as actively malicious and prioritize blocking it at the network level. The use of Cloudflare infrastructure complicates traditional IP-based blocking, so DNS-level or domain-based restrictions are recommended. Organizations should monitor for any internal traffic attempting to connect to this domain, as it may indicate compromised endpoints or users who have engaged with the phishing lure. While the giveaway theme is evident from the page title, the absence of further details means defenders should remain vigilant for secondary payloads or follow-on attacks, such as credential harvesting or malware distribution, which may occur post-redirect.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Registration: on-fleek.app
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain on-fleek.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias · 1 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comAnálise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
“The PhishDestroy system has identified this domain as a phishing threat, flagged both by our internal parser and reported by users. We also cross-reference with public databases and other antivirus systems.”
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo