thorswap-xplorer[.]pages[.]dev
“Thorswap Explorer — Blockchain Transaction Explorer”
thorswap-xplorer.pages.dev — 未验证. 品牌冒充:Across; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 6/91 (ADMINUSLabs, alphaMountain.ai, CyRadar, Fortinet, LevelBlue); PhishDestroy score 73/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain is flagged as an active high-risk brand impersonation threat specifically targeting Across bridge users through a fraudulent blockchain transaction explorer interface. The page, titled Thorswap Explorer — Blockchain Transaction Explorer, mimics legitimate cryptocurrency infrastructure to deceive users into disclosing wallet credentials or approving malicious transactions under the guise of Across protocol functionality. Analysis indicates the domain thorswap-xplorer.pages.dev was registered on August 26, 2025, through Cloudflare, Inc. Infrastructure analysis reveals the domain resolves to IPv6 address 2606:4700:310c::ac42:2f61, hosted on Cloudflare's network (AS13335) in the United States. The SSL certificate is issued by Google Trust Services (WE1), providing a false sense of legitimacy. Detection metrics show the domain appears on one security blocklist, with VirusTotal reporting 1/95 security vendors flagging the domain as malicious. The single vendor detection suggests either early-stage deployment or evasion techniques targeting less common detection systems. Mitigation against this brand impersonation threat requires multi-layered verification procedures. Users should cross-reference all blockchain explorer domains against official protocol documentation, particularly when interacting with cross-chain bridge interfaces. Wallet software should be configured to display full domain verification warnings before transaction signing. Network-level protections should incorporate the identified IPv6 address and domain into blocklists, while monitoring for additional domains using similar naming patterns (thorswap-xplorer, across-explorer variants). Incident responders should examine transaction patterns from the identified infrastructure for potential unauthorized fund movements or approval phishing attempts targeting Across protocol users.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of thorswap-xplorer.pages.dev · checked Mar 7, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。