interface-aave[.]xyz
interface-aave.xyz is an active domain created on 25 March 2026 and hosted behind Cloudflare infrastructure (IP 188.114.97.3, located in Canada). The domain is registered through Dynadot LLC and uses a Google Trust Services / WE1 SSL certificate. HTTP responses return status 403 and the page title is limited to “Just a moment…”, indicating that content is not publicly rendered. The site is classified as a brand‑impersonation campaign targeting Aave and is described as an investment scam. Infrastructure analysis shows a Gridinsoft trust score of 0/100 and the domain appears in eight AlienVault OTX pulses and three security blocklists, including PhishDestroy, MetaMask and SEAL. The domain resolves to Cloudflare nameservers eleanor.ns.cloudflare.com and jakub.ns.cloudflare.com. No public malware detections have been reported, but the presence on multiple blocklists and the low trust score suggest malicious intent. Defenders should block or monitor DNS queries for the domain and associated IP address, enforce URL filtering, and consider adding the domain to internal threat intelligence feeds. Ongoing observation of any changes to HTTP content or certificate details is advised, as the current 403 response may be altered to serve phishing pages.
Threat Response Pipeline
Public Blocklist Status
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive