modeswap[.]xyz
“Mode App - The Modular DeFi L2 - Airdrop”
Сводка доказательств
Analysis of modeswap.xyz indicates that the domain was registered on February 21, 2026 and is currently offline. The site resolved to the IP address 172.67.176.133, which is owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. The TLS certificate identifier "WE1" was observed, but no further certificate details are disclosed. The page title returned by the server was "Mode App - The Modular DeFi L2 - Airdrop," suggesting a lure targeting cryptocurrency users seeking airdrops.
Intelligence tags the site as employing an "Airdrop Scam" phishing kit and classifies the overall activity as a Crypto Scam. Five of ninety-three VirusTotal scanners flagged the domain as malicious, and the domain appears on five external security blocklists. Multiple community blocklists, including PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura, have already listed the domain as malicious, reinforcing the detection consensus.
Because the site is offline, direct content analysis could not be performed, leaving the precise phishing payload and credential‑capture mechanisms unverified. Defenders should continue to block traffic to 172.67.176.133, add modeswap.xyz to corporate deny lists, and monitor for any re‑hosting or fast‑flux behavior that might resurrect the scam under a new address. Ongoing observation of Cloudflare‑hosted IP ranges for similar airdrop‑related titles is recommended, as threat actors frequently reuse the same infrastructure for multiple campaigns.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
6 внешних источников под наблюдением Совпадений нет
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание