llamaandswap[.]com
“Llamaswap”
Збережене виявлення
Виявлено маскування
- Тип маскування
bot_redirect_safe- Оцінка маскування
- 4/6
Зведення доказів
The domain llamaandswap.com was registered on July 23, 2025 through Dynadot LLC and is currently hosted on Cloudflare's network (AS13335, United States). DNS resolution points to the IP address 188.114.97.3 and the domain uses the nameservers eugene.ns.cloudflare.com and tiffany.ns.cloudflare.com. The site presents an HTTP 301 redirect and serves content over TLS with a Let’s Encrypt R12 certificate, employing Google Web Server, HTTP/3, and HSTS. Security scoring systems assign the domain a zero‑point trust rating (0/100) on Gridinsoft, and it appears on one external blocklist. PhishDestroy has already listed the domain as malicious. VirusTotal analysis shows that four out of ninety‑five scanning engines have flagged the domain, reinforcing the high‑risk assessment. The page title returned by the server is “Llamaswap,” and the intelligence categorizes the activity as a cryptocurrency‑related brand‑impersonation campaign targeting the “across” brand. Publicly available content beyond the title has not been captured, so the exact phishing or fraud mechanisms employed on the landing page remain unknown. No additional infrastructure such as command‑and‑control servers, payment processors, or malware drops has been observed in the current data set. The lack of visible payloads does not diminish the risk, as the domain’s primary objective appears to be brand impersonation for cryptocurrency scams. Defenders should immediately block resolution of llamaandswap.com at the DNS layer and add the IP address 188.114.97.3 to network‑level deny lists. Email security gateways should be updated to flag any messages containing URLs that resolve to this domain. Continuous monitoring of Cloudflare‑hosted assets for similar naming patterns and the reuse of the eugene.ns.cloudflare.com / tiffany.ns.cloudflare.com nameservers is recommended. Incident response teams should also watch for emerging variants that may copy the “Llamaswap” title or target the same “across” brand.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Хронологія виявлення
-
VirusTotal
4 → 5
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології
Виявлено 3 технології з високою впевненістю
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of llamaandswap.com · checked Mar 2, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога