curve-exchanges[.]typedream[.]app
“Curve Exchange | Curve.finance”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
Analysis on July 24, 2026 indicates that the domain curve-exchanges.typedream.app is currently offline but was previously serving a page titled “Curve Exchange | Curve.finance”. The site resolved to IP address 104.21.37.85, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. HTTP probing returned a 404 status, suggesting the content was removed or never existed at the time of testing. The TLS certificate presented was issued by Google Trust Services under the WE1 root, confirming the use of a legitimate certificate chain but not authenticating the underlying brand. The domain was registered through the Typedream platform, a website‑builder service that often hosts short‑lived malicious pages. Reputation services show a Scamadviser trust score of 11/100 and the domain appears on a single security blocklist.
PhishDestroy has already blocked the host, and VirusTotal recorded a single positive detection out of 95 scanning engines, indicating at least one vendor flagged the domain as malicious. Technical fingerprints reveal a stack consisting of Node.js, React, Next.js, and multiple Google Cloud services (Trace, CDN) together with Cloudflare Browser Insights, consistent with a modern web application framework rather than a static landing page. The observable evidence points to a brand‑impersonation campaign targeting Curve users, classified as a crypto‑related scam. The page title explicitly references Curve.finance, and the threat actor likely intended to harvest credentials or lure victims into a fraudulent exchange flow. No further details about the landing page content, login form, or payload have been captured because the site is offline.
The lack of disclosed nameservers and the reliance on a third‑party builder make attribution difficult, but the use of Cloudflare’s network and Google‑issued TLS suggests the infrastructure was deliberately chosen for anonymity and rapid deployment.
Data Coverage
مؤشرات الأمان
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
المخطط الزمني للاكتشاف
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
التقنيات
حُدّدت ١٠ تقنيات عالية الثقة
تحليل VirusTotal
الأدلة المؤرشفة
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب