swisborg-walletauth[.]webflow[.]io
“SwissBorg® Wallet® | Getting started with SwissBorg”
swisborg-walletauth.webflow.io — Conteúdo indisponível. Representação da marca: Genericcrypto; Tipo de golpe: Wallet/seed Phishing. Resumo das evidências: VirusTotal 16/94 (ADMINUSLabs, alphaMountain.ai, CyRadar, Emsisoft, Forcepoint ThreatSeeker); URLQuery 2 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. Registrador: Webflow.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies swisborg-walletauth.webflow.io as an elevated-risk crypto drainer campaign actively harvesting private keys and tokens. The domain masquerades as a legitimate wallet authentication portal, luring victims with false claims of enhanced security or transaction validation. This strain specifically targets cryptocurrency holders by prompting wallet connections under the guise of identity verification, then exfiltrating funds via malicious smart contract interactions. This domain was flagged by 11 out of 95 VirusTotal security vendors, indicating moderate detection but clear malicious intent. It resolves to IP 104.18.36.248 and leverages a Google Trust Services SSL certificate to appear legitimate. The infrastructure is hosted on Webflow’s subdomain service, which has been exploited to deploy phishing kits rapidly. Historical WHOIS data reveals the domain was created recently, though exact creation date is obscured by privacy protections. It has not yet propagated widely across major blocklists such as Google Safe Browsing or PhishTank, suggesting an emerging but highly targeted threat. Mitigation for this crypto drainer requires immediate action: users must avoid clicking links or connecting wallets to unsolicited authentication prompts. Enable hardware wallet signing for all transactions and revoke any unauthorized smart contract approvals via tools like Etherscan’s token approval checker. Organizations should deploy real-time DNS filtering to block access to this domain and its IP, while threat hunters should monitor for similar Webflow-hosted drainers using seed f19a37 as a behavioral indicator. Always verify endpoints via official channels and never input private keys or seed phrases into web forms.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | swisborg-walletauth.webflow.io |
malicious | Sinkholed |
| Cloudflare DNS | swisborg-walletauth.webflow.io |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 3 identified
Visual website builder with hosted publishing.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of swisborg-walletauth.webflow.io · checked Apr 1, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo