jupiterswap-en-help[.]typedream[.]app
“Jupiterswap: Advanced DEX Aggregator on Solana”
jupiterswap-en-help.typedream.app — Контент недоступен. Олицетворение бренда: Jupiter; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 1/91 (LevelBlue); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Регистратор: Typedream.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain jupiterswap-en-help.typedream.app is flagged as a brand‑impersonation site targeting the Jupiter brand. The page title returned by the server is “Jupiterswap: Advanced DEX Aggregator on Solana,” which aligns with the declared impersonation of Jupiter’s decentralized‑exchange services. DNS resolution points to the IP address 188.114.97.3, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. The domain is registered through the Typedream platform, and the SSL certificate presented is issued by Google Trust Services under the WE1 certificate authority, indicating a legitimate TLS chain but not mitigating the malicious intent.
HTTP response code 404 was observed, suggesting the resource is no longer serving content; the domain is currently listed as offline. Nevertheless, the indicator persists on three independent security blocklists and has been actively blocked by PhishDestroy, MetaMask, and SEAL, confirming its presence in multiple threat‑intel feeds. VirusTotal analysis shows that 1 of 91 security scanners flagged the domain, reinforcing the suspicion of malicious activity. Nameserver data could not be retrieved (NS_NOT_FOUND), which limits deeper infrastructure correlation.
For defenders, the immediate recommendation is to ensure the domain is blocked at DNS and proxy layers, update web‑filter policies to include the three known blocklists, and monitor for any re‑registration or new IP assignments that could resurrect the site. Continuous observation of Typedream‑hosted domains for similar brand‑impersonation patterns is advised, as the platform may be leveraged for future campaigns. The lack of a live page limits further forensic detail, but the combination of brand‑specific page title, Cloudflare hosting, SSL issuance, and multiple blocklist entries provides sufficient confidence to treat the domain as a confirmed threat.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание