sushi-ena[.]top
“Stake SUSHI | Sushi”
sushi-ena.top — 内容不可用 (HTTP 502). 品牌冒充:SushiSwap; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 6/93 (alphaMountain.ai, BitDefender, CyRadar, Fortinet, G-Data); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 74/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain sushi-ena.top was registered on February 21, 2026 and is currently listed as offline. DNS resolution points to the IPv4 address 107.172.83.150, which belongs to the HostPapa hosting provider (AS36352) and is geolocated in the United States. An SSL certificate identified as R11 is present on the site, indicating that HTTPS was configured before the domain was taken down. The page title returned by the server is "Stake SUSHI | Sushi," which aligns with the declared scam type of a crypto scam targeting users of the SushiSwap platform.
The domain is specifically marked as impersonating SushiSwap, a well‑known decentralized exchange, and therefore falls under the brand‑impersonation threat category. Detection data show that six of ninety‑three security vendors on VirusTotal flagged the domain, suggesting a moderate level of malicious confidence among scanners. The domain appears on four independent blocklists—PhishDestroy, Polkadot, Enkrypt, and Codeesura—demonstrating that multiple threat‑intelligence feeds have recognised it as abusive. No additional public intelligence, such as OTX or Safe Browsing entries, is available beyond the listed blocklist memberships.
Given the limited exposure window (the domain was active for only a few months before being taken offline) and the lack of publicly disclosed payload or credential‑harvesting mechanisms, the precise operational details of the campaign remain uncertain. Defenders should update their URL filtering and DNS sink‑hole rules to include sushi-ena.top, monitor the hosting provider’s IP range for related activity, and consider the six VirusTotal detections as a signal to prioritize related alerts. Continuous observation of the associated IP address and any future registrations under the same registrar is recommended to detect potential re‑use of the infrastructure for further brand‑impersonation attempts.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。