VirusTotal
13 / 91
“Trojan - The Ultimate On-Chain Trading Experience”
bsw.online — Gizlenmiş · ulaşılabilir (HTTP 403). Marka kimliğine bürünme: Solana; Dolandırıcılık türü: Crypto Drainer. Kanıt özeti: VirusTotal 13/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker); 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 100/100. Kayıt kuruluşu: Namecheap.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
13 / 91
3/12
checked — no match recorded
23 community references
Bildirprovider verdict: clean
Bildirsaklanan rapor
Bildir Analiz tamamlandı
BildirChecked; no threat flag recorded
BildirPhishDestroy identifies bsw.online as an active crypto drainer masquerading as a legitimate on-chain trading platform, as confirmed by its title 'Trojan - The Ultimate On-Chain Trading Experience'. This domain was specifically engineered to trick users into connecting cryptocurrency wallets and draining funds through deceptive smart contract interactions. The page promotes fraudulent 'on-chain trading' services while operating solely to exploit unsuspecting victims through malicious on-chain transactions. Security vendors widely recognize this threat, with 6 of 95 VirusTotal scanners already detecting its malicious nature, and major platforms like MetaMask and SEAL have preemptively blocked access to this domain. Technical analysis reveals this domain exhibits multiple red flags consistent with crypto drainer infrastructure. Registered on November 16, 2025 through NAMECHEAP INC, the domain resolves to IP address 104.21.54.42 and leverages a Let's Encrypt SSL certificate to appear legitimate. Notably, this domain has already been identified by four major security blocklists including OISD and Maltrail, demonstrating widespread recognition across the security community. The combination of recent domain registration, association with known malicious infrastructure, and active blocking by security solutions confirms this is not a false positive but rather part of an emerging campaign targeting cryptocurrency users. If you've visited bsw.online, disconnect your wallet immediately and revoke any permissions you may have granted. Check your wallet transaction history for any unusual outgoing transfers and report suspicious activity to your security team. Consider transferring remaining funds to a new wallet with enhanced security measures. Enable wallet protection features like transaction simulation if available, and remain vigilant for follow-up phishing attempts. Monitor your devices for potential malware infections that may have resulted from this interaction.
Full extracted values, their blockchain and collection source. An address found in page content does not establish who controls it.
https://t.me/trojanStored page referenceIoC extraction recorded 2026-07-29 02:05:48 UTC
Sayfa, tarayıcı benzeri bir ziyaretçiye bir yanıt, tarayıcıya veya güvenlik tarayıcısına ise başka bir yanıt sunuyordu. Gizleme tekniği, yalnızca inceleme yapan kişileri gerçek açılış sayfasından uzak tutmak amacıyla kullanılır.
content_divergencecloudflareTarayıcı notu: alive_content: raw=waf_403; http=403; via=https_proxy; server=cloudflare
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Edge-IP itibarı bu etki alanıyla ilişkilendirilmez.
ezra.ns.cloudflare.comjocelyn.ns.cloudflare.comLocation describes the IP network.
d6a389ebdf6f63771e07449e8e8d003a0f503b10a261ba893046e00369c1e041Saved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of bsw.online · checked Apr 20, 2026
11 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
118 kayıtlı benzer alan adı
118 kaydın 100 kadarı gösteriliyor
1 topluluk üyesi tarafından bildirildi; ilk görülme 20.04.2026
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Template-based draft · optional AI wording assistance requires separate consent
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraŞüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirSon kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleCanlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin