ethereum-exchange-swap[.]com
“Ethereum Exchange Swap – Instant ETH Trading Without KYC or Registration”
ethereum-exchange-swap.com — Ошибка сервера (HTTP 502). Олицетворение бренда: Ethereum; Тип мошенничества: Wallet/seed Phishing. Сводка доказательств: VirusTotal 11/95 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, Fortinet); Spamhaus DBL_PHISH; 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 83/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain ethereum-exchange-swap.com was registered on August 05, 2025 through NiceNIC International Group Co., Limited and currently resolves to the IP address 104.21.32.1 hosted by Cloudflare, Inc. (AS13335) in the United States. No SSL certificate is present on the site, and the HTTP service is now reported as offline. The page title captured during the active phase reads "Ethereum Exchange Swap – Instant ETH Trading Without KYC or Registration," indicating a wallet/seed phishing campaign that targets users of the Ethereum brand.
The infrastructure has been assigned a Gridinsoft trust score of 0 out of 100 and appears on six security blocklists. Multiple defensive products have already blocked the domain, including PhishDestroy, MetaMask, Polkadot, SEAL, and Enkrypt. VirusTotal analysis shows that 11 of 95 scanned security vendors flagged the domain, reinforcing the assessment of malicious intent.
The risk level is classified as high, reflecting the potential for credential and seed‑phrase harvesting. Defenders should ensure the domain remains sink‑holed or blocked in DNS filters, update local blocklists with the observed IP and hostname, and educate Ethereum users about the danger of providing private keys or seed phrases to unsolicited services. Continuous monitoring is advised in case the site is re‑hosted or the domain is re‑registered, as the current offline status does not preclude future activity.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-18 03:01:15 UTC
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание