jupiter-swap-app-downlod[.]typedream[.]app
“Jupiter Swap: The Ultimate DEX Aggregator on Solana”
jupiter-swap-app-downlod.typedream.app — İçerik kullanılamıyor. Marka kimliğine bürünme: Jupiter; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 1/91 (LevelBlue); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Kayıt kuruluşu: Typedream.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, jupiter-swap-app-downlod.typedream.app, was observed serving a page with the title “Jupiter Swap: The Ultimate DEX Aggregator on Solana.” The page title explicitly references the Jupiter brand, matching the reported brand‑impersonation classification. DNS resolution returned the IPv4 address 188.114.97.3, which belongs to ASN 13335 operated by Cloudflare, Inc., and is geolocated in the United States. No authoritative name servers were discovered, and the HTTP response code returned 404, indicating that the resource is no longer available. The site presented a valid TLS certificate issued by Google Trust Services under the subject “WE1,” confirming that HTTPS was correctly negotiated at the time of capture.
VirusTotal recorded a single positive detection out of ninety‑one scanned scanners, confirming that at least one security vendor identified malicious characteristics. Independent blocklist feeds list the domain on three separate repositories, and the domain is explicitly blocked by PhishDestroy, MetaMask, and SEAL, reinforcing the consensus that it constitutes a brand‑impersonation threat. The registrar information shows that the domain was created through Typedream, a website‑building service, which is frequently abused for fast‑deployment of fraudulent pages. Gridinsoft’s proprietary trust scoring assigned a rating of zero out of one hundred, reflecting an extremely low reputation.
The combination of a brand‑specific page title, a Cloudflare‑hosted IP, a single VirusTotal flag, multiple blocklist entries, and a zero trust score collectively indicate a high likelihood that the domain was used to deceive users seeking legitimate Jupiter services. Uncertainty remains regarding the specific payload or credential‑harvesting mechanism, as the page content could not be retrieved due to the 404 response and the domain’s offline status. Defenders should continue to block the domain at perimeter and endpoint filters, add the IP address 188.114.97.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Site Yapılandırma Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin