Перейти к отчёту о безопасности
Checked 09.08.2026 Ref F59708AA

MALICIOUS — CRITICAL

Проверка домена swsink.com на фишинг и безопасность

swsink[.]com

Security analysis of swsink.com covers observed phishing indicators, infrastructure evidence, current status, and defensive guidance.

83/100 evidence score · Critical
VirusTotal
3/91
Blocklists
2 · MetaMask, SEAL
Доступность
Непроверенный
Report / Add Evidence Appeal this listing
No capture stored

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Этот домен был отмечен как вредоносный
Механизмы безопасности сообщают об обнаружении: 3. Публичные черные списки, сообщающие о совпадении: 2. Будьте предельно осторожны — не вводите учетные данные или личную информацию.
Jump to section
Краткий обзор отчёта

swsink.com — Непроверенный. Сводка доказательств: VirusTotal 3/91 (Gridinsoft, Seclookup, SOCRadar); Spamhaus DBL_SPAM; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. Регистратор: NiceNIC.

Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.

Evidence Analysis

Ref F59708AA

Analysis of swsink.com indicates that the domain was registered on 27 April 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is currently resolved to the IPv4 address 193.24.123.205, which is attributed to a Russian hosting entity identified as Prospero OOO. The authoritative name servers are ns3.my-ndns.com and ns4.my-ndns.com. The site was served over HTTPS using a Let’s Encrypt certificate issued under the E7 series, confirming the presence of TLS but offering no evidence of legitimate ownership.

Threat intelligence feeds list the domain on three public blocklists and it appears in a single AlienVault OTX pulse, indicating prior detection by at least one community source. VirusTotal scans show three of ninety‑one security vendors flagged the domain, reinforcing the suspicion of malicious use. Independent security products have assigned a Gridinsoft trust score of zero out of one hundred and have recorded blocks by PhishDestroy, MetaMask, and SEAL, further corroborating its classification as a phishing vector.

The domain’s risk level is marked as elevated, yet its current online status is offline, suggesting the infrastructure may have been taken down or is temporarily inactive. Defenders should continue to monitor DNS queries for the listed name servers and the associated IP address, enforce outbound filtering to block connections to this host, and incorporate the domain and IP into existing blocklists and intrusion‑detection signatures. Because the underlying payload, targeted brand, or specific phishing kit has not been publicly disclosed, analysts should treat any future re‑activation as potentially hostile and prioritize rapid investigation of any related traffic or email indicators.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
3 det.
OTX references
Сертификат TLS
Просрочен или не проверен -22d
Возраст
3 mo
Зафиксированный статус
Непроверенный
PhishDestroy
DestroyList
В списке
Охват данных12 recorded checks
VirusTotal 3 / 91 URLQuery не проверено PhishStats не проверено OTX 1 community reference CF Radar no data URLScan capture not submitted URLScan verdict вердикт недоступен DNS-блокировки не проверено TLS Просрочен или не проверен WHOIS 3 mo old Снимок экрана не зафиксировано Цепочка перенаправлений не исследовано
Данные сетевой безопасности Registrar context
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

Процесс реагирования на угрозы

Открытие
Checks
Reports
Доступность
8/10
Угроза устранена
swsink.com обнаружены и помещены в очередь для полного анализа
15.06.2026
VirusTotal
3/91 recorded on VirusTotal
18.07.2026
Google Safe Browsing
28.04.2026
Обнаружение списков заблокированных адресов
Найдено в 2 blocklists: MetaMask, SEAL
09.08.2026
OTX Community References
1 community publication reference on AlienVault OTX. References are not vendor verdicts and are excluded from the evidence score.
27.04.2026
Registrar Context: NiceNIC
Separate registrar research is available. Registrar association is contextual and is not scored as an independent detection.
Technical Analysis Recorded
Отчет содержит сохраненные технологии или результаты судебно-медицинской экспертизы.
09.08.2026
Complaint Draft Available
Подача не фиксируется. Вы можете создать проект, просмотреть его и самостоятельно отправить в соответствующий орган.
Опубликовано «DestroyList»
15.06.2026
Доступность не подтверждена
Последний ответ недостаточен для классификации текущего наличия.

Статус в публичных блок-листах

Аналитика доменов

Домен
Сервер / ASN AS200593 PROSPERO OOO
Репутация IP abuse score 0/100 0 reports checked 13.07.2026
IP-адрес 193.24.123.205 RU
ГеолокацияRU St Petersburg, RU
СетьAS200593 · Prospero OOO
Обратный поиск IPviewdns.info → rapiddns.io →
РегистрацияСоздано 27.04.2026 (104d)
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Впервые обнаружено15.06.2026
Серверы имёнns4.my-ndns.com
TLS Fingerprint
TLS Observationvalid from 19.04.2026scanned 27.04.2026
ICANN OVERSIGHT

Аккредитация и контекст RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Ничего не отправляется автоматически.

Latest Classified Outcome 2026-08-09 02:56:44 UTC

Primary outcome Неизвестно reason: Probe Inconclusive 20% confidence
Attribution source: Current Http Probe
Evidence layers Availability: Unreachable Content: Unknown DNS: Resolved Registration: Active
Latest HTTP observation Неизвестно Probe Inconclusive 20% 2026-08-09 02:56:44 UTC
RDAP registration Активен NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 RDAP HTTP 200 source: Rdap Status Collector clientDeleteProhibitedclientTransferProhibited expires 2027-04-19 09:57:00 UTC checked 2026-08-05 19:04:54 UTC
Observed timeline last reachable: 2026-08-08 22:15:11 UTC
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
Пожаловаться на этот домен Предоставьте доказательства и помогите защитить других

Анализ VirusTotal

3 / Поставщики средств безопасности 91 отметили этот домен
View on VT
Last analyzed
Gridinsoft
Seclookup
SOCRadar
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.

Европол
Найдите официальный канал отчетности для вашей страны ЕС
National police directory
Остерегайтесь мошенников, предлагающих услуги по восстановлению данных! Преступники могут снова связаться с жертвами, притворяясь следователями, адвокатами или агентами по восстановлению. Не платите авансовые платежи и не делитесь учетными данными. Узнайте больше о мошенничестве при получении компенсаций →

Сообщите об этом в местные органы власти

Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.

Каталог 97 стран
Черновик по шаблону • помощь AI с формулировками включается только с отдельного согласия. Просмотрите и отправьте его самостоятельно
Вставить этот отчетRead-only HTML widget
HTML · IFRAME

Вставить этот отчет

Разместите эту информацию об угрозах на своём сайте или в блоге

embed.html
<iframe
  src="https://phishdestroy.io/ru/embed/domain/swsink.com"
  title="PhishDestroy threat report for swsink.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Очень искреннее благодарственное письмо

Генератор сатирических черновиков

Получатель
Контекст сборов

Это сатирический черновик. Суммы сборов являются оценочными; мы не утверждаем, что они точно относятся к этому домену.