swapvelocity[.]io
“Velocity”
swapvelocity.io — 隐形 · 可达. 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); cloaking observed; PhishDestroy score 96/100. 注册商: NameCheap.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain swapvelocity.io was registered on April 02, 2026 through NameCheap, Inc. It is currently classified as a high‑risk generic_phishing site and remains active as of the report date (July 12, 2026). The observed page title is “Velocity”, and the site presents a DEX‑type scam that aligns with known airdrop‑kit behavior. Infrastructure analysis reveals that the domain resolves to the IPv4 address 216.198.79.1, which is geolocated to the United States and associated with Lefkoff Industries. DNS resolution is performed by dns1.registrar-servers.com and dns2.registrar-servers.com. HTTP requests receive a 307 temporary redirect, and the TLS certificate is issued by Let’s Encrypt (R12), indicating a valid but freely‑issued certificate. Threat‑intel signals include eight AlienVault OTX pulses referencing the domain, a Gridinsoft trust score of 0 / 100, and a single detection out of 95 security vendors on VirusTotal. The domain is listed on one public blocklist and is actively blocked by PhishDestroy. The observed phishing kit corresponds to an “Airdrop Scam”, reinforcing the DEX‑scam classification. Defenders should prioritize blocking DNS resolution for swapvelocity.io and enforce network‑level filtering of its IP address 216.198.79.1. Monitoring for the 307 redirect pattern and the Let’s Encrypt certificate fingerprint can aid in early detection. Uncertainty remains regarding any additional command‑and‑control infrastructure that may be provisioned behind the same IP, so continuous enrichment of passive DNS and traffic logs is recommended.
威胁响应 Pipeline
公共封禁名单状态
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。