api3[.]sushiswap[.]one
Сводка доказательств
This domain is flagged as an elevated-risk brand impersonation threat targeting SushiSwap users through a fraudulent API endpoint. Infrastructure analysis indicates the domain is designed to mimic legitimate SushiSwap API infrastructure, likely to harvest cryptocurrency wallet credentials or facilitate unauthorized transactions. The specific threat involves credential theft and wallet-draining attacks, where victims are tricked into interacting with the malicious endpoint under the false pretense of accessing SushiSwap services. Multiple technical indicators confirm the malicious nature of api3.sushiswap.one. The domain was registered on September 16, 2025, through Dynadot LLC and currently resolves to IP address 172.67.143.233. VirusTotal reports 3 out of 95 security vendors flagging the domain as malicious, while it appears on at least one security blocklist. The page title 'Just a moment...' suggests the use of Cloudflare or similar services to obfuscate backend infrastructure. Trust scores from Scamadviser (46/100) and Gridinsoft (0/100) further indicate high-risk activity. The domain has since been taken offline, but residual DNS records or cached pages may still pose a threat. Mitigation against this type of brand impersonation requires multi-layered defenses. Users should verify domain authenticity by cross-referencing official SushiSwap documentation and avoiding interactions with unofficial API endpoints. Organizations should implement DNS-based blocking for known malicious IPs (e.g., 172.67.143.233) and monitor for newly registered domains containing 'sushiswap' or similar variations. Cryptocurrency wallet users should enable hardware-based authentication and review transaction approvals carefully. Security teams should prioritize monitoring for credential reuse attempts, particularly from users who may have interacted with the domain prior to its takedown.
Data Coverage
Сигналы безопасности
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 10.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
-
VirusTotal
0 → 3
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Registration: sushiswap.one
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain sushiswap.one behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криминалистическая аналитика
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание