governance-ethena[.]finance
The domain governance-ethena.finance has been identified as a generic phishing threat with an elevated risk level. The domain does not appear to masquerade as any specific brand, nor is there evidence of a drainer kit typically associated with cryptocurrency phishing. The page title 'Just a moment...' suggests an attempt to delay users, possibly while malicious content is loaded or credentials are harvested. This domain was registered through NiceNIC International Group Co., Limited, a registrar often used in the registration of questionable domains.
Technical indicators reveal several concerning factors. VirusTotal flags the domain with a detection count of 14 out of 95 security vendors, indicating a significant level of suspicion. The domain resolves to the IP address 172.67.160.5, and it incorporates technologies such as Cloudflare Browser Insights and HTTP/3, which may provide enhanced security features but does not mitigate its inherent risk as a phishing site. The domain was created on March 13, 2026, and it is currently blocked by security entities such as PhishDestroy and ScamSniffer, and appears on two security blocklists. The Scamadviser trust score is critically low at 1/100, while Gridinsoft assigns a trust score of 0/100.
Currently, governance-ethena.finance is offline, reducing its immediate threat potential. However, the domain's history and associated IP address may still pose risks if reactivated under similar pretenses. It is recommended that users remain vigilant for email communications or web links directing to this domain. Security teams should ensure that this domain remains on blocklists and monitor for any similar domains that may emerge. Continuous updates to security protocols and awareness among users can help mitigate risks associated with phishing domains like governance-ethena.finance.
Network Security Intelligence Registrar context
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-15 03:03:31 UTC
Forensic Intelligence
Technologies · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of governance-ethena.finance · checked Jun 26, 2026
Evidence & External Reports
PD-20260313-AD24E4 Recipient: abuse@nicenic.net, compliance@icann.org Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive