sushi-weeth[.]xyz
“恭喜,站点创建成功!”
sushi-weeth.xyz — 内容不可用 (HTTP 502). 品牌冒充:SushiSwap; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 1/93 (Gridinsoft); PhishDestroy score 63/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis conducted on July 22, 2026 identifies the domain sushi-weeth.xyz as an active component of a cryptocurrency-related scam targeting users of the SushiSwap platform. The site returned an HTTP response indicating it is offline at the time of analysis, and the page title retrieved during prior scans reads “恭喜,站点创建成功!” which translates to “Congratulations, site created successfully!”. This title does not reference SushiSwap but the domain’s metadata and the documented impersonation of SushiSwap confirm the intended victim profile. The domain was registered on February 21, 2026 and resolves to the IPv4 address 107.172.83.150, an address owned by HostPapa (ASN 36352) located in the United States. The hosting provider and geographic location are consistent with other low-cost abuse‑friendly services often leveraged for malicious campaigns.
The SSL certificate presented by the host is identified as “R10”, a generic issuance that provides transport encryption but offers no assurance of legitimacy. VirusTotal analysis shows that one out of ninety-three security vendors flagged the domain, indicating at least a minimal detection by automated scanners. The domain is listed on a single security blocklist and has been actively blocked by the PhishDestroy remediation service, demonstrating that at least one defensive entity has taken action to prevent client exposure. Current intelligence gaps include the absence of a public Safe Browsing verdict, lack of additional blocklist citations, and no publicly shared OTX or threat-intel signatures referencing this exact FQDN.
Consequently, the full scope of the campaign—such as the number of associated domains, command-and-control infrastructure, or payload delivery mechanisms—remains undetermined. Defenders should add sushi-weeth.xyz to their deny-list or block-list configurations, monitor DNS queries for resolutions to 107.172.83.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。