jupiterswap-en-help[.]typedream[.]app
“Jupiterswap: Advanced DEX Aggregator on Solana”
jupiterswap-en-help.typedream.app — Контент недоступний. Уособлення бренду: Jupiter; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 1/91 (LevelBlue); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Реєстратор: Typedream.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain jupiterswap-en-help.typedream.app is flagged as a brand‑impersonation site targeting the Jupiter brand. The page title returned by the server is “Jupiterswap: Advanced DEX Aggregator on Solana,” which aligns with the declared impersonation of Jupiter’s decentralized‑exchange services. DNS resolution points to the IP address 188.114.97.3, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. The domain is registered through the Typedream platform, and the SSL certificate presented is issued by Google Trust Services under the WE1 certificate authority, indicating a legitimate TLS chain but not mitigating the malicious intent.
HTTP response code 404 was observed, suggesting the resource is no longer serving content; the domain is currently listed as offline. Nevertheless, the indicator persists on three independent security blocklists and has been actively blocked by PhishDestroy, MetaMask, and SEAL, confirming its presence in multiple threat‑intel feeds. VirusTotal analysis shows that 1 of 91 security scanners flagged the domain, reinforcing the suspicion of malicious activity. Nameserver data could not be retrieved (NS_NOT_FOUND), which limits deeper infrastructure correlation.
For defenders, the immediate recommendation is to ensure the domain is blocked at DNS and proxy layers, update web‑filter policies to include the three known blocklists, and monitor for any re‑registration or new IP assignments that could resurrect the site. Continuous observation of Typedream‑hosted domains for similar brand‑impersonation patterns is advised, as the platform may be leveraged for future campaigns. The lack of a live page limits further forensic detail, but the combination of brand‑specific page title, Cloudflare hosting, SSL issuance, and multiple blocklist entries provides sufficient confidence to treat the domain as a confirmed threat.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога