jup-ag[.]gd
“Jupiter Exchange: The Leading Jupiter DEX for Optimal Swaps”
jup-ag.gd — 服务器错误 (HTTP 502). 品牌冒充:Jupiter; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 13/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 89/100. 注册商: NiceNIC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain is flagged as a high-risk brand impersonation threat specifically targeting Jupiter, a decentralized exchange (DEX) platform. Analysis indicates the site operates as a crypto drainer, leveraging fake DEX interfaces to deceive users into connecting wallets and authorizing malicious transactions. The impersonation tactic is designed to exploit trust in the Jupiter brand, presenting itself as a legitimate swap platform to facilitate unauthorized fund transfers. Infrastructure analysis reveals multiple technical indicators of compromise. The domain jup-ag.gd was registered on March 04, 2026, through NiceNIC International Group Co., Limited, a registrar frequently associated with malicious domains. It resolves to the IP address 130.12.180.128 and is detected by 13 out of 95 security vendors on VirusTotal. The site is blocked by MetaMask, PhishDestroy, and SEAL, and appears on three security blocklists. Additional technical data includes a Gridinsoft trust score of 0/100 and the use of PHP, Nginx, and OpenResty technologies. The page title, 'Jupiter Exchange: The Leading Jupiter DEX for Optimal Swaps,' directly mimics legitimate Jupiter branding to enhance credibility. Mitigation against this brand impersonation threat requires immediate action from both users and security teams. Users should verify domain authenticity by cross-referencing official Jupiter communication channels and avoiding any interaction with jup-ag.gd. Wallet providers are advised to enforce strict blocklist policies, particularly for domains registered through high-risk registrars like NiceNIC International Group Co., Limited. Security teams should monitor for similar impersonation patterns, including lookalike domains, unusual PHP-based DEX interfaces, and IP ranges associated with 130.12.180.128. Transaction simulation tools can help detect crypto drainer activity by identifying unauthorized swap approvals or fund transfers to unfamiliar addresses. Proactive DNS filtering and real-time phishing detection mechanisms are recommended to prevent access to this domain and its associated infrastructure.
网络安全情报 Registrar context
威胁响应 Pipeline
公共封禁名单状态
Latest Classified Outcome 2026-08-05 18:54:00 UTC
所用技术 · 3 identified
Server-side scripting language designed for web development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web platform based on Nginx with LuaJIT for scalable web apps.
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of jup-ag.gd · checked Jun 26, 2026
证据与外部报告
PD-20260304-1878EF Recipient: abuse@virtualine.org 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。