dex[.]rhea-finance[.]network
“RHEA Finance”
dex.rhea-finance.network — المحتوى غير متوفر. انتحال العلامة التجارية: Ledger; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 1/93 (Gridinsoft); PhishDestroy score 56/100.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of dex.rhea-finance.network, a domain flagged for brand impersonation targeting Ledger, reveals confirmed phishing infrastructure linked to a crypto scam. The domain was registered on February 21, 2026, and resolved to the IP address 206.217.128.210, hosted on AS36352 (HostPapa) in the United States. As of July 24, 2026, the site is offline, having been blocked by PhishDestroy and listed on at least one security blocklist. The page title, 'RHEA Finance,' suggests an attempt to present itself as a financial or crypto-related service, though the exact content and functionality remain unconfirmed due to its current offline status. One of 93 security vendors on VirusTotal flagged the domain, indicating detection by at least one major security provider.
The domain's SSL certificate, classified as R10, may reflect low trust or non-standard issuance, though further forensic analysis would be required to determine its exact significance. Gridinsoft assigned a trust score of 0/100, reinforcing its classification as malicious infrastructure. No additional details regarding the phishing kit, payload delivery mechanism, or victim interaction patterns are available at this time. Defenders should treat this domain as confirmed malicious infrastructure associated with crypto scams.
Network-level blocking of 206.217.128.210 and the domain itself is recommended. Organizations should monitor for any re-emergence of this infrastructure under new domains or IPs, particularly those mimicking financial or crypto services. Given the impersonation of Ledger, users of the targeted brand should be alerted to potential follow-up attacks leveraging stolen credentials or wallet information. Further investigation into the hosting provider (AS36352) may reveal additional related infrastructure.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب