app-boros-pendle.finance
“Rewards | Boros”
Evidence Summary
Analysis of app-boros-pendle.finance indicates that the domain was registered on July 24, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is currently hosted on the IP address 188.114.96.3. The authoritative name servers are kip.ns.cloudflare.com and meera.ns.cloudflare.com, both belonging to Cloudflare’s DNS network, which is frequently used by both legitimate services and malicious operators to obscure infrastructure. The domain remains active as of the report date and is listed on a single security blocklist. VirusTotal scanning shows that one out of ninety‑one anti‑malware engines flagged the domain, suggesting at least one vendor has identified malicious behavior associated with it. PhishDestroy also reports the domain as blocked, reinforcing the classification as a phishing vector.
The limited detection surface—only one blocklist entry and a single vendor flag—means that broader community awareness of the threat is still emerging. No additional intelligence such as Safe Browsing status, Open Threat Exchange reports, SSL certificate details, or HTTP response codes is available, leaving the full scope of the hosting environment and potential payload delivery mechanisms uncertain. The use of Cloudflare name servers does not, by itself, confirm malicious intent, but combined with the registrar information, the active status, and the existing blocklist entries, the risk profile aligns with a high‑confidence phishing indicator. Defenders should add app-boros-pendle.finance to URL filtering rules and blocklist it at perimeter and endpoint layers.
Network monitoring should include alerts for DNS queries to the two Cloudflare name servers that resolve to 188.114.96.3, and any outbound connections to that IP should be inspected or denied pending further investigation. Continuous re‑scanning on VirusTotal and other multi‑engine platforms is recommended to capture any escalation in detection counts.
Network Security Intelligence Registrar context
Forensic History & Detection Timeline
-
Domain Status Transition Jul 28, 2026 · 00:18 UTCDomain state transitioned from dead to alive.
-
Domain Status Transition Jul 27, 2026 · 12:53 UTCDomain state transitioned from alive to dead.
Threat Response Pipeline
Public Blocklist Status
Detection-evasion analysis
Cloaking suspected: scanner and visitor titles differ
Not yet scanned
No crawler-versus-browser difference has been recorded yet
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not yet scanned
- Last cloaking scan
- Server header seen by scanner
cloudflare
Scanner note: cloudflare_ban: raw=cf_phishing_block; http=403; via=https_proxy; server=cloudflare; provider_error=cloudflare_phishing_interstitial
Provider response during scan: cloudflare_phishing_interstitial
Stored Capture · 2 sources
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-09-23 02:45:10 UTC
Technologies · 6 identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of app-boros-pendle.finance · checked Jul 24, 2026
Lookalike domains
36 stored lookalike domains
Show all (24)
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive