v3-thorswap[.]xyz
“THORSwap”
v3-thorswap.xyz — Контент недоступний (HTTP 502). Уособлення бренду: 1inch; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 3/93 (alphaMountain.ai, Forcepoint ThreatSeeker, Seclookup); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 74/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain v3-thorswap.xyz was registered on 21 February 2026 and is presently taken offline. Infrastructure analysis shows that the hostname resolves to the IPv4 address 163.61.188.2, which is announced by ASN 153568 (NEW DHAKA HARDWARE) and geolocated to the United States. The site presented a TLS certificate identified as R10, indicating a short‑lived or self‑signed certificate. The HTTP response header reported a page title of “THORSwap”, which does not match the advertised brand.
Threat intelligence attributes the campaign to a brand‑impersonation effort targeting the cryptocurrency aggregator 1inch, classifying the activity as a crypto‑scam. The domain appears on four independent security blocklists, specifically PhishDestroy, Polkadot, Enkrypt, and Codeesura. VirusTotal analysis recorded three positive detections out of ninety‑three scanning engines, confirming malicious intent. The risk assessment is elevated, reflecting both the targeted brand and the observed malicious infrastructure.
Uncertainty remains regarding the exact payload delivered, the command‑and‑control infrastructure, and whether the domain was actively serving phishing pages before its takedown. Defenders should immediately block the IP address 163.61.188.2 and the domain v3-thorswap.xyz at perimeter and DNS layers, update detection signatures to include the observed TLS fingerprint and page title, and monitor for any re‑registration attempts under the same second‑level domain. Continuous observation of the listed blocklists and periodic re‑scanning on VirusTotal are recommended to capture potential re‑activation.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога