aavegov[.]com
“Aave”
The domain aavegov.com is identified as a high-risk brand impersonation threat targeting Aave, a decentralized finance protocol. Analysis confirms this domain was designed to deceive users by mimicking the official Aave platform, likely for fraudulent purposes such as credential theft or unauthorized transactions. The domain is currently offline, but prior activity and infrastructure details warrant continued monitoring. Technical indicators reveal the domain was registered through PDR Ltd. d/b/a PublicDomainRegistry.com on April 18, 2026, an unusually future-dated registration that may indicate an attempt to evade immediate detection. It resolved to the IP address 104.21.42.12 and utilized a Let's Encrypt SSL certificate, a common tactic to appear legitimate. The domain was flagged by 15 of 95 security vendors on VirusTotal and appears on three security blocklists. Additional scrutiny from security providers assigned a trust score of 0/100, further confirming its malicious intent. The page title displayed 'Aave,' reinforcing the impersonation effort. Current status indicates the domain has been taken offline, likely due to enforcement actions or infrastructure changes. However, the risk of reemergence or similar domains remains high. Organizations and users are advised to block the domain and associated IP address at the network level. Security teams should monitor for newly registered domains with similar naming patterns or infrastructure ties. End users should verify the authenticity of any platform claiming affiliation with Aave by cross-referencing official communication channels and avoiding interaction with untrusted domains.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of aavegov.com · checked Jun 26, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive