shushi---cdn---swap.webflow.io
“Swap | Sushi”
shushi---cdn---swap.webflow.io is a confirmed crypto drainer scam impersonating SushiSwap. Detected by 14/95 security vendors, this active threat steals wallet.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Сводка доказательств
This domain, shushi---cdn---swap.webflow.io, is flagged as an active crypto drainer scam specifically designed to impersonate the legitimate decentralized exchange SushiSwap. Analysis indicates the threat actor has deployed a malicious interface mimicking the authentic SushiSwap platform, likely utilizing a drainer kit to siphon cryptocurrency assets from victims' wallets upon connection. The page title, 'Swap | Sushi,' directly corresponds to the branding of the legitimate SushiSwap platform, a tactic employed to deceive users into interacting with the fraudulent site. Infrastructure analysis reveals the domain is hosted on Webflow's content delivery network, resolving to the IP address 104.18.36.248. The domain is flagged by 14 out of 95 security vendors on VirusTotal, indicating a moderate-to-high detection rate. The SSL certificate is issued by Google Trust Services, providing a false sense of security to potential victims. No historical registration data is publicly available due to Webflow's hosting model, which obscures traditional WHOIS records. Google Safe Browsing currently lists this domain as unsafe, and it appears on multiple blocklists, including those maintained by cryptocurrency security firms and threat intelligence platforms. As of the latest verification, shushi---cdn---swap.webflow.io remains active and continues to pose a significant risk to users. The domain's infrastructure, combined with its impersonation of a well-known DeFi platform, suggests a targeted campaign aimed at cryptocurrency holders. Users are strongly advised to avoid interacting with this domain and to verify the authenticity of any platform before connecting wallets or entering sensitive information. Wallet providers and security platforms are encouraged to add this domain to their blocklists to mitigate further risk. The remaining threat level is classified as high due to the domain's active status and the irreversible nature of cryptocurrency transactions.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Проверка по блок-листам
11 внешних источников под наблюдением · снимок от 10.09.2026
11 внешних источников под наблюдением Совпадений нет
Технологии · 3 identified
Webflow is Software-as-a-Service (SaaS) for website building and hosting.
webflow.com 100% уверенностиCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of shushi---cdn---swap.webflow.io · checked Jun 30, 2026
Технологии
Выявлено 3 технологии с высокой уверенностью
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание