etherex[.]foundation
Phishing and security check for etherex.foundation
“Dashboard - Etherex Exchange”
Analysis of etherex.foundation, created on February 21 2026, shows it was used to impersonate Discord in a social media phishing campaign. The site presented the page title "Dashboard - Etherex Exchange" and was secured with an SSL certificate identified as WE1. Infrastructure inspection reveals the domain resolved to IP address 188.114.97.3, located in the United States and associated with AS13335 Cloudflare, Inc. VirusTotal recorded a single positive detection out of ninety‑three scanners, indicating at least one vendor identified malicious behavior.
The domain appears on two independent blocklists, PhishDestroy and ScamSniffer, confirming external threat intel corroborates its malicious nature. Gridinsoft assigned a trust score of zero out of one hundred, reflecting an extremely low reputation. Current status is offline, suggesting the hosting service has been taken down or the site is otherwise inaccessible, yet remnants may persist in DNS caches or client systems that have previously resolved the address.
Defenders should continue to block the domain at network perimeter and endpoint filters, monitor for any resurgence of the IP or similar Cloudflare‑hosted assets, and consider adding the domain to internal allow‑list exclusions only after thorough verification. Further investigation is needed to determine the exact phishing kit employed, the content of the login interface, and whether additional infrastructure (command‑and‑control or credential‑harvesting endpoints) is linked to the same IP range. Continuous threat‑intel feeds should be consulted for updates, and any user reports of unsolicited Discord‑related communications referencing etherex.foundation should be escalated for incident response.
Threat Response Pipeline
Public Blocklist Status
Forensic Intelligence
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive