nvb-sushi[.]xyz
“403 Forbidden”
nvb-sushi.xyz — Контент недоступний. Уособлення бренду: SushiSwap; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 6/93 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet, Sophos); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 74/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain nvb-sushi.xyz was registered on February 21, 2026 and is currently classified as a brand impersonation campaign targeting SushiSwap. Infrastructure analysis shows the domain resolves to the IPv4 address 107.172.87.131, which is owned by AS36352 HostPapa and geolocated to the United States. An SSL certificate was observed on the host, identified as rating R10, but the site returns an HTTP 403 Forbidden response and the page title is reported as "403 Forbidden," indicating that the content is not publicly accessible at the time of analysis. The site is listed on four known security blocklists and has been actively blocked by PhishDestroy, Polkadot, Enkrypt, and Codeesura.
Reputation services assign a Gridinsoft trust score of 0 out of 100, reflecting a very low confidence in the domain's legitimacy. VirusTotal scans reveal that six of ninety-three security vendors flag the domain as malicious, providing additional corroboration of its abusive nature. The campaign’s declared scam type is a crypto scam, consistent with the impersonation of the SushiSwap brand.
Defenders should continue to block nvb-sushi.xyz at network and endpoint layers, monitor for any reactivation of the domain, and consider adding the associated IP address to deny lists. Because the site presently returns a 403 status and is offline, further content analysis is limited; however, the combination of registration timing, hosting details, low trust score, blocklist presence, and vendor detections strongly supports treating the domain as malicious. Ongoing vigilance is advised to detect any future resurrection of the infrastructure or related domains.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога