sign-sushi[.]lat
sign-sushi.lat — 内容不可用 (HTTP 502). 品牌冒充:SushiSwap; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 1/95 (Gridinsoft); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 74/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of sign-sushi.lat, created on February 21, 2026, shows that the domain is currently taken offline but retains several indicators of malicious intent. The domain resolves to IP address 104.21.112.1, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. An SSL certificate identified as WE1 is present, suggesting that the site employed HTTPS encryption despite its brief operational window. The page title returned by the server is "Just a moment...," a generic placeholder often used in malicious redirection chains, and no further content has been publicly captured.
The domain explicitly impersonates SushiSwap, a well‑known decentralized exchange, and is classified as a crypto‑related scam. VirusTotal reports a single detection out of 95 security vendors, indicating at least one scanner flagged the site as suspicious. Additionally, the domain appears on four independent blocklists—PhishDestroy, Polkadot, Enkrypt, and Codeesura—reinforcing the consensus that it is associated with illicit activity. No public Safe Browsing entry, OTX pulse, or additional intelligence has been disclosed, leaving the full extent of the threat unknown.
Given the concrete evidence—Cloudflare hosting, SSL presence, deceptive page title, confirmed brand impersonation, and inclusion on multiple blocklists—defenders should treat sign-sushi.lat as a high‑confidence malicious indicator. Recommended actions include adding the domain and its resolving IP to network‑level deny lists, updating endpoint protection signatures to flag any future resolution attempts, and monitoring for any resurrection of the domain or related subdomains. Continuous observation of Cloudflare‑hosted assets linked to the IP may reveal subsequent campaigns that reuse the same infrastructure. Until the domain remains offline, any traffic to sign-sushi.lat should be blocked to prevent potential crypto‑draining or credential‑theft attempts targeting SushiSwap users.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。