Güvenlik raporuna geç
Etki alanı güvenliği ve tehdit istihbaratı
bsw.online favicon

bsw.online

“Trojan - The Ultimate On-Chain Trading Experience”

Kayıt kuruluşu
Namecheap
Resolved IP
104.21.54.42
Registered
16.11.2025
Tehdit kararı Kritik
Kullanılabilirlik Gizlenmiş · ulaşılabilir Gizleme kontrolleri aracılığıyla gözlemlenen ulaşılabilirlik Gözlemlenen
Source: HTTP probe
VirusTotal algılamaları: 13/91 Saklanan engelleme listesi eşleşmeleri: 2 Marka kimliğine bürünme: Solana Bilinen son aktif
OTX: 23 refs 20.04.2026 Solana CDN
API
Bu alan adı, zararlı olarak işaretlenmiştir
Güvenlik motorları bir algılama bildiriyor: 13. Bir eşleşme bildiren genel engellenenler listeleri: 2. Çok dikkatli olun — kimlik bilgilerini veya kişisel bilgileri girmeyin.
Rapor özeti

bsw.online — Gizlenmiş · ulaşılabilir (HTTP 403). Marka kimliğine bürünme: Solana; Dolandırıcılık türü: Crypto Drainer. Kanıt özeti: VirusTotal 13/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker); 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 100/100. Kayıt kuruluşu: Namecheap.

Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.

VirusTotal
VirusTotal
13 det.
OTX references
DNS Security
3/12
URLScan
URLScan
TLS sertifikası
Süresi dolmuş veya doğrulanmamış
Yaş
11 mo
Gözlemlenen durum
Gizlenmiş · ulaşılabilir 403
PhishDestroy
DestroyList
Listelenmiş

Source evidence

8 sources

VirusTotal

13 / 91

Bildir

DNS engellemeleri

3/12

PhishStats

checked — no match recorded

OTX

23 community references

Bildir

CF Radarı

provider verdict: clean

Bildir

URLScan capture

saklanan rapor

Stored URLScan capture preview
Bildir

URLScan verdict

Analiz tamamlandı

Bildir

Google Safe Browsing

Checked; no threat flag recorded

Bildir
Ağ Güvenliği İstihbaratı
DNS Provider Blocks 3 / 12
Controld Adblock Controld Family Controld Malware

Kanıt özeti

Kritik
VirusTotal
13/91
OTX
23 community refs
URLScan
Stored capture

PhishDestroy identifies bsw.online as an active crypto drainer masquerading as a legitimate on-chain trading platform, as confirmed by its title 'Trojan - The Ultimate On-Chain Trading Experience'. This domain was specifically engineered to trick users into connecting cryptocurrency wallets and draining funds through deceptive smart contract interactions. The page promotes fraudulent 'on-chain trading' services while operating solely to exploit unsuspecting victims through malicious on-chain transactions. Security vendors widely recognize this threat, with 6 of 95 VirusTotal scanners already detecting its malicious nature, and major platforms like MetaMask and SEAL have preemptively blocked access to this domain. Technical analysis reveals this domain exhibits multiple red flags consistent with crypto drainer infrastructure. Registered on November 16, 2025 through NAMECHEAP INC, the domain resolves to IP address 104.21.54.42 and leverages a Let's Encrypt SSL certificate to appear legitimate. Notably, this domain has already been identified by four major security blocklists including OISD and Maltrail, demonstrating widespread recognition across the security community. The combination of recent domain registration, association with known malicious infrastructure, and active blocking by security solutions confirms this is not a false positive but rather part of an emerging campaign targeting cryptocurrency users. If you've visited bsw.online, disconnect your wallet immediately and revoke any permissions you may have granted. Check your wallet transaction history for any unusual outgoing transfers and report suspicious activity to your security team. Consider transferring remaining funds to a new wallet with enhanced security measures. Enable wallet protection features like transaction simulation if available, and remain vigilant for follow-up phishing attempts. Monitor your devices for potential malware infections that may have resulted from this interaction.

Extracted from stored page analysis

Observed indicators

0 wallet · 1 Telegram

Full extracted values, their blockchain and collection source. An address found in page content does not establish who controls it.

Telegram
https://t.me/trojanStored page reference

IoC extraction recorded 2026-07-29 02:05:48 UTC

Tespitten kaçma delilleri

Gizleme durumu doğrulandı: Tarayıcılar ve ziyaretçiler farklı içerik görüyor

Gözlemlenen Tarayıcılara ve ziyaretçilere farklı içerikler sunuldu

Sayfa, tarayıcı benzeri bir ziyaretçiye bir yanıt, tarayıcıya veya güvenlik tarayıcısına ise başka bir yanıt sunuyordu. Gizleme tekniği, yalnızca inceleme yapan kişileri gerçek açılış sayfasından uzak tutmak amacıyla kullanılır.

Kaydedilmiş gizleme bayrağı
Gözlemlenen
Gizleme türü
content_divergence
Gizleme puanı
2/6
Son gizleme taraması
Tarayıcı tarafından algılanan sunucu başlığı
cloudflare

Tarayıcı notu: alive_content: raw=waf_403; http=403; via=https_proxy; server=cloudflare

Güvenlik tarayıcısında görüntülenen başlıkDNS points to prohibited IP | bsw.online | Cloudflare
Tarayıcı ziyaretçisine gösterilen başlıkTrojan - The Ultimate On-Chain Trading Experience
TDS'da canlı parmak izi kontrolü
Bu panel açıkken, PhishDestroy tarayıcısından çalıştırıldığında yedi Keitaro parmak izi ve bir tarayıcı-crawler karşılaştırması görüntülenir.
Bekleme

Kaydedilen görüntü · 2 captures

Sayfa başlığı
Trojan - The Ultimate On-Chain Trading Experience
Impersonates
Solana Telegram TikTok YouTube
TLS sertifikası
Hostname coverage not recorded · Düzenleyen Let's Encrypt · stored validity ends in 79 days

Domain details

Alan adı
URLScan Verdict Analiz tamamlandı score 0 report ↗
IP Context Cloudflare shared edge origin IP hidden Edge-IP itibarı bu etki alanıyla ilişkilendirilmez.
OTX Tags 2026-04activeall-domainsblocklistcontentcryptoalan adlarıdrainerfraudlivemonthlyphishdestroyphishingscam
Kayıt kuruluşu Namecheap US(US)
Kötüye kullanım iletişim bilgisi["abuse@namecheap.com", "registry@namecheap.com"]
ICANN Kayıt KuruluşuICANN Lookup (RDAP) →
KayıtOluşturuldu 16.11.2025 (329d) — Expires 16.11.2026
HTTP Durumu403 Forbidden
Cloaking Cloaking Detected Content divergence · score 2/6
alive_content: raw=waf_403; http=403; via=https_proxy; server=cloudflare
server: cloudflare title: DNS points to prohibited IP | bsw.online | Cloudflare
checked 11.10.2026
Teknik ayrıntılarProvenance & timestamps
İlk Kez Tespit Edildi20.04.2026
DOM Analysisanalyzed 09.10.2026score 100/1004 brand signals
IoC Extractionscanned 29.07.20260 wallet · 1 Telegram IoC
Submitted URLhttp://bsw.online/
ICANN OVERSIGHT

Akreditasyon ve RAA bağlamı

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Hiçbir şey otomatik olarak gönderilmez.

Network & certificates

Stored technical evidence

Network & DNS

Shared CDN edge
Resolved IP
104.21.54.42
Network ASN
AS13335
Organization
Cloudflare, Inc.
Observed location
Toronto, CA
Server header
cloudflare

Edge-IP itibarı bu etki alanıyla ilişkilendirilmez.

Ad sunucuları 2

  • ezra.ns.cloudflare.com
  • jocelyn.ns.cloudflare.com

Location describes the IP network.

TLS sertifikası

Issuer
Let's Encrypt
Valid from
2026-09-15 08:21:11
Valid until
2026-12-14 08:21:10
Hostname coverage
Hostname coverage not recorded
Validity
Within stored validity dates
Collection time
2026-10-10 10:03:17 UTC
Collection source
PhishDestroy collector
Certificate fingerprintd6a389ebdf6f63771e07449e8e8d003a0f503b10a261ba893046e00369c1e041

Saved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.

viewdns.info · 104.21.54.42rapiddns.io

Latest Classified Outcome 2026-10-11 10:20:56 UTC

Primary outcome Reachable but protected reason: HTTP access restricted 65% confidence
Attribution Cloudflare mechanism: Access Restriction source: Current Http Probe
Evidence layers Availability: Reachable but protected Content: Unknown DNS: Resolved Registration: Unknown
Latest HTTP observation Reachable but protected HTTP access restricted Cloudflare Access Restriction 65% 2026-10-11 10:20:56 UTC
RDAP registration Bilinmiyor
Observed timeline last reachable: 2026-10-11 10:20:56 UTC
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
Teknolojiler · 6 identified
Detected via Cloudflare Radar · Wappalyzer engine
Bu Alan Adını Bildir Kanıt sunun ve başkalarını korumaya yardımcı olun

VirusTotal Analizi

13 / 91 güvenlik sağlayıcıları bu alanı işaretledi
View on VT
Last analyzed Previous stored snapshot: 13 detections
alphaMountain.ai
BitDefender
CyRadar
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Lionic
Seclookup
SOCRadar
Sophos
VIPRE
Site Performans Analizi

Google PageSpeed Insights — mobile performance audit of bsw.online · checked Apr 20, 2026

65
Needs Work
Performance
FCP
4.35s
First Contentful Paint
LCP
5.55s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
151ms
Total Blocking Time
SI
5.25s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Tehdit Müdahale Pipeline

Keşif
Analysis
Monitoring

11 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.

Tehdit Alındı
bsw.online tespit edildi ve kapsamlı analiz için sıraya alındı
20.04.2026
URLScan.io Capture
Kaydedildi URLScan report with capture artifacts
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
VirusTotal
13/91 recorded on VirusTotal
29.09.2026
Engellenenler Listesi Algılama
Şu kaynakta bulunur: 2 blocklists: MetaMask, SEAL
11.10.2026
OTX Community References
23 community publication references on AlienVault OTX. References are not vendor verdicts and are excluded from the evidence score.
01.10.2026
DNS Security Blocks
Blocked by 3 of 12 checked DNS providers: Controld adblock, Controld family, Controld malware
Brand Impersonation
Impersonation of Solana
Forensic Evidence Collected
Stored evidence from URLScan.io, stored screenshot
Technical Analysis Recorded
Rapor, depolanan teknolojiyi veya adli analiz sonuçlarını içerir.
11.10.2026
DestroyList Yayınlandı
20.04.2026
Monitoring Continues
Etki alanı erişilebilir durumda kalır veya erişimi kısıtlıdır; gelecekteki kontroller bu gözlemi güncelleyebilir.
How we investigate & report

Public scans, evidence and abuse channels

We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.

01Public scans & evidence collection10 sources and tool groups
urlscan.io Screenshot · DOM · HTTP

Capture the rendered page, requests and visible infrastructure.

VirusTotal Multi-engine verdicts

Compare the available engine results and retain the analysis timestamp.

Cloudflare Radar DNS · certificates · categories

Inspect a public scan and its recorded network and classification data.

AlienVault OTX Threat-intelligence pulses

Look for indicator references and related community intelligence.

Wayback Machine Historical evidence

Compare archived captures and preserve historical context.

crt.sh Certificate Transparency

Inspect certificate records and related hostnames.

DNS Security Filters Quad9 · AdGuard · CleanBrowsing

Compare security resolver responses and record observed blocking.

Web-Check Surface inspection

Inspect the public DNS, TLS, HTTP and technology surface.

02Abuse reports & follow-upRegistrar, hosting and security channels
  1. Identify the responsible provider. Match registration and hosting records to the relevant abuse contact.
  2. Prepare an evidence package. Include the URL, public scan references, captures and the recorded observations.
  3. Send the report. Keep outgoing report records and recipient information when available.
  4. Recheck and publish updates. Track later scanner verdicts, provider responses and site availability.

Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.

Genel Engelleme Listesi Durumu

Benzer alan adları

118 kayıtlı benzer alan adı

oslana.com transposition salana.com vowel-swap selana.com vowel-swap sloana.com transposition solanacom.com various solano.com vowel-swap solanu.com vowel-swap solona.com vowel-swap soluna.com vowel-swap sulana.com vowel-swap aolana.com replacement asolana.com insertion
Tümünü göster (88)
colana.com bitsquatting dolana.com replacement dsolana.com insertion esolana.com insertion olana.com omission qolana.com bitsquatting rolana.com bitsquatting s-olana.com hyphenation s01ana.com homoglyph sglana.com bitsquatting silana.com replacement skolana.com insertion slana.com omission so-lana.com hyphenation soana.com omission sodana.com bitsquatting soiana.com homoglyph soilana.com insertion sokana.com replacement sola-na.com hyphenation solaa.com omission solaana.com repetition solaba.com replacement solafa.com bitsquatting solaha.com replacement solahna.com insertion solaja.com bitsquatting solala.com bitsquatting solama.com homoglyph solan-a.com hyphenation solan.com omission solanc.com bitsquatting solane.com bitsquatting solani.com bitsquatting solanna.com homoglyph solans.com replacement solany.com replacement solanz.com replacement solara.com homoglyph solarna.com homoglyph solasna.com insertion solayna.com insertion solena.com bitsquatting solina.com bitsquatting solkana.com insertion sollana.com insertion solmana.com insertion solna.com omission soloana.com insertion solpana.com insertion solsana.com insertion solwana.com insertion solyana.com insertion solyna.com replacement solzana.com insertion somana.com bitsquatting sonana.com bitsquatting sopana.com replacement soplana.com insertion splana.com replacement spolana.com insertion ssolana.com repetition swolana.com insertion wolana.com bitsquatting xn--solaa-03b.com homoglyph xn--solan-jwa.com homoglyph xn--solna-zqa.com homoglyph xolana.com replacement xsolana.com insertion yolana.com replacement zolana.com replacement sklana.com bitsquatting sohana.com bitsquatting solana0.com addition solana2.com addition solana3.com addition solana4.com addition solana6.com addition solana7.com addition solana9.com addition solanaa.com addition solanab.com addition solanac.com addition solanad.com addition solanae.com addition solanaf.com addition solanag.com addition solanah.com addition

118 kaydın 100 kadarı gösteriliyor

Topluluk raporları

1 topluluk üyesi tarafından bildirildi; ilk görülme 20.04.2026

Kayıtlı raporlar
1
Bildirilen benzersiz URL’ler
1
Kabul edildi1

Kanıtlar ve Dış Raporlar

Derinlemesine Analiz

Bu Siteden Etkilendiniz mi?

5 evidence signal groups linked 0 reports recorded Gizlenmiş · ulaşılabilir
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.

Europol
AB ülkeniz için resmi raporlama kanalını bulun
National police directory
Kurtarma dolandırıcılarına dikkat edin! Suçlular, araştırmacı, avukat veya kurtarma görevlisi gibi davranarak mağdurlarla tekrar iletişime geçebilir. Peşin ücret ödemeyin veya kimlik bilgilerinizi paylaşmayın. Geri ödeme dolandırıcılığı hakkında daha fazla bilgi edinin →

Yerel Yetkililere Bildirin

resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.

97 ülke rehberi

Template-based draft · optional AI wording assistance requires separate consent

Yapay zeka destekli taslak — olay ayrıntıları yapay zeka sağlayıcısı tarafından işlenir · Kendiniz inceleyin ve gönderin

Herhangi Bir Alan Adını Kontrol Et

Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi

Şimdi Tara

Oltalama Olayını Bildir

Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun

Bildir

Canlı Tehdit Akışı

Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri

İzle

Gelişmelerden Haberdar Olun, Güvende Kalın

Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin

Canlı Tehdit Akışı Bu İlanı İtiraz Et
HTML · IFRAME

Bu Raporu Yerleştir

Bu tehdit bilgisini web sitenizde veya blogunuzda paylaşın

embed.html
<iframe
  src="https://phishdestroy.io/tr/embed/domain/bsw.online"
  title="PhishDestroy threat report for bsw.online"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>