wenjuan[.]themisswap[.]org
“卷王问卷考试系统”
wenjuan.themisswap.org — Контент недоступен. Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 1/93 (SOCRadar); PhishDestroy score 55/100. Регистратор: PDR.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain wenjuan.themisswap.org was registered on 21 February 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com. The site presented the page title “卷王问卷考试系统” and operated without an SSL certificate, indicating that traffic was unencrypted. DNS resolution points to the Cloudflare address 104.21.19.180, which is associated with ASN 13335, a Cloudflare network located in the United States. The domain appeared on three known security blocklists and received a Gridinsoft trust score of zero out of one hundred, reflecting a highly malicious reputation.
Malware scanning on VirusTotal recorded a single positive detection out of ninety‑three vendors, reinforcing the suspicion of malicious activity. The infrastructure was flagged by PhishDestroy, MetaMask, and SEAL, and the domain is currently listed as offline. Classification from the intelligence set identifies the activity as a crypto‑related scam, though the exact mechanism of the fraud is not disclosed. The lack of HTTPS, low trust score, presence on multiple blocklists, and the positive vendor detection collectively substantiate the classification.
While the page content has not been captured, defenders should continue to block the domain at network perimeters, update URL filtering rules, and monitor for any re‑appearance of the host or related subdomains. Additional scrutiny of recent registrations from the same registrar may reveal a broader campaign. The evidence presented, including registration details, hosting attribution, blocklist listings, and vendor detection, provides a concrete basis for remediation and further investigation.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: themisswap.org
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain themisswap.org behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
PD-20260202-DE4798 Recipient: abuse@publicdomainregistry.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание