nomi-swap[.]pages[.]dev
“Suspected phishing site | Cloudflare”
Сводка доказательств
The domain nomi-swap.pages.dev was observed as a crypto‑focused phishing site and is currently taken offline. Infrastructure analysis shows the domain resolves to IP address 104.21.96.1, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The authoritative nameservers are blair.ns.cloudflare.com and finley.ns.cloudflare.com, both operated by Cloudflare. The site presented a TLS certificate issued by Google Trust Services / WE1, indicating a valid HTTPS endpoint, and the HTTP response returned a 403 status code, consistent with Cloudflare’s generic phishing block page titled “Suspected phishing site | Cloudflare.” Registration data reveals the domain was created on February 21, 2026 through Cloudflare, Inc. The technology stack includes HSTS, Cloudflare services, and HTTP/3 support.
Reputation signals are uniformly negative: Gridinsoft assigns a trust score of 0/100, Scamadviser rates the domain at 11/100, and the site appears on two independent blocklists—PhishDestroy and ScamSniffer—both of which have flagged it as malicious. VirusTotal analysis shows that one of ninety‑three scanning engines identified the domain as suspicious. The risk level is elevated, reflecting the combination of a recent creation date, low trust scores, and active blocklist listings. Defenders should immediately add nomi-swap.pages.dev and its resolved IP 104.21.96.1 to deny lists across web proxies, DNS filtering solutions, and endpoint firewalls.
Continuous monitoring of the domain’s registration and DNS records is advised to detect any re‑registration attempts. Given the Cloudflare front‑end, threat actors may shift to alternative subdomains; security teams should consider broader pattern matching on the “pages.dev” suffix and the observed nameserver pair. Incident response teams should treat any alerts related to this domain as high priority, isolate affected user sessions, and verify that no credential or cryptocurrency wallet data were exfiltrated.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
9 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Данные сообщества
1 сообщение сообщества
КатегорияPHISHING
@hitterace Telegram
Криминалистическая аналитика
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of nomi-swap.pages.dev · checked Apr 12, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание