# aethirreward.live — SUSPICIOUS > Explore the phishing threat posed by aethirreward.live, its detection status, and recent takedown details. ## Summary PhishDestroy identifies aethirreward.live as a domain involved in generic phishing activities. Classified as a medium-risk threat, this domain was reportedly created on February 21, 2026. Its primary use was to deceive users by mimicking legitimate services or offers, aiming to steal sensitive information such as login credentials or financial data. Technical indicators for aethirreward.live include its registration through a now-defunct registrar, contributing to its offline status. The domain appeared on one known security blocklist and was flagged by four security vendors in VirusTotal scans. These findings suggest a limited but credible phishing infrastructure. No additional subdomains or IP associations have been publicly reported, indicating a relatively isolated setup typical of short-lived phishing campaigns. As of now, aethirreward.live is offline, having been taken down likely due to the phishing activity and associated detections. The domain's removal reduces immediate user risk, though the campaign's timeframe remains unclear. PhishDestroy recommends users remain vigilant against similar domains exhibiting suspicious registration patterns or blocklist inclusion, as attackers frequently cycle through domains to evade detection. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 403) - Page title: Just a moment... ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - Registrar: NiceNIC International Group Co., Limited - Country: HK - IP: 172.67.157.101 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: ["adam.ns.cloudflare.com", "harleigh.ns.cloudflare.com"] - SSL Issuer: Google Trust Services / WE1 ## Detection Status - VirusTotal: 4 vendors flagged Vendors: ["CRDF", "Fortinet", "Gridinsoft", "Seclookup"] - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["PhishDestroy"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019a431b-9619-7403-b060-6615191c95c4.png - Cloudflare Radar: https://radar.cloudflare.com/scan/28fc63d7-7f7b-44bc-b213-cef9cab2359e - PhishDestroy: https://phishdestroy.io/domain/aethirreward.live/ - LLM endpoint: https://phishdestroy.io/domain/aethirreward.live/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/aethirreward.live/ Last updated: 2026-03-19