alf[.]cash
“Alfacash - Buy, Sell & Exchange Bitcoin, Litecoin, Ethereum, XRP, EOS, Tether...”
Registered with NICENIC INTERNATIONAL GROUP CO., LIMITED just three days ago, alf[.]cash operates from the IP address 188.114.96.3. The domain has already been blocklisted once, indicating previous detection by cybersecurity services. This short lifespan and blocklisting suggest ongoing malicious activity, further underscoring the site's dangerous nature.
Currently, alf[.]cash remains active and is being monitored closely by PhishDestroy. We have reported this domain to relevant authorities to ensure its swift removal from the web, and continuous efforts will be made to track its operations and protect users from potential harm.
Threat Response Pipeline
Public Blocklist Status
Evidence Capture
Domain Intelligence
robert.ns.cloudflare.com
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If you have interacted with this domain, entered personal information, or connected a cryptocurrency wallet — take immediate action. Below are resources to help you report the incident and protect yourself.
Report to Your Local Authorities
Select your country to see local cybercrime reporting contacts and complaint templates.
Related Domain Reports
Other Domains on 188.114.96.3
More Domains at NICENIC INTERNATIONAL GROUP CO., LIMITED
About This Report: alf.cash
This domain security report for alf.cash is maintained by PhishDestroy's automated threat intelligence pipeline. Our system continuously monitors this domain across 95 security vendors on VirusTotal, 1 public blocklists, URLScan.io.
The site displays a page titled “Alfacash - Buy, Sell & Exchange Bitcoin, Litecoin, Ethereum, XRP, EOS, Tether and many other digi...”.
alf.cash has been flagged by 2 security vendors as of February 27, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.
Stay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive



URLScan Report