VirusTotal
10 / 95
“Linea Ignition”
This report addresses the domain linea-ignition.breivis.network. The site's page title was "Linea Ignition" and it impersonated the brand "aave" in a cryptocurrency scam. The threat posed is financial fraud, as the site likely attempted to trick users into connecting their cryptocurrency wallets or providing credentials under the false pretense of an official Aave-related service.
Technical evidence shows the domain was flagged by 10 out of 95 VirusTotal vendors. It was detected by security vendors including ChainPatrol, BitDefender, CRDF, CyRadar, and Fortinet. Two blocklists contained this domain. The IP address was 188.114.97.3, located in the United States, hosted by AS13335 Cloudflare, Inc. The domain was created on 2026-02-21 and used an SSL certificate type WE1.
The site is currently down or offline. Its GridinSoft trust rating is 0 out of 100, and the DOM risk score is 80, indicating a high risk. Based on this evidence, the domain represents a confirmed malicious threat associated with cryptocurrency fraud.
Full extracted values, their blockchain and collection source. An address found in page content does not establish who controls it.
0x085f80Df643307e04f23281F6fdbfAA13865E852Format validated · Domain analysis0x09666eaf650dc52cece84b1bcd2dd78997d239c7Format validated · Domain analysis0x14EfcC1Ae56e2fF75204Ef2Fb0DE43378d0beaDAFormat validated · Domain analysis0x176211869ca2b568f2a7d4ee941e073a821ee1ffFormat validated · Domain analysis0x179DfD3eCDC6f5B8F8788584F3289D10c6F1afb8Format validated · Domain analysis0x5c1bf4b7563c460282617a0304e3cde133200f70Format validated · Domain analysis0x5dc74003c0a9d08eb750b10ed5b02fa7d58d4d1eFormat validated · Domain analysis0x6667f117b936f17aa62d0fd3228ad0db046985e6Format validated · Domain analysis0x73045fe421f1f1719946cc664cf6020b0c183854Format validated · Domain analysis0x76e5d2033268f053cbe8b65abbd00db66fa6d39bFormat validated · Domain analysis0x8bf8EdC911Ab3f0ea4a27c51Cb88b57ccE5356f1Format validated · Domain analysis0x90e8a5b881d211f418d77ba8978788b62544914bFormat validated · Domain analysis0x9aC2F0A564B7396A8692E1558d23a12d5a2aBb1FFormat validated · Domain analysis0xCBeF9be95738290188B25ca9A6Dd2bEc417a578cFormat validated · Domain analysis0xF4712fC5E6483DE9e1Ff661D95DD686664327086Format validated · Domain analysis0xa219439258ca9da29e9cc4ce5596924745e12b93Format validated · Domain analysis0xa7ada0d422a8b5fa4a7947f2cb0ee2d32435647dFormat validated · Domain analysis0xa8A02E6a894a490D04B6cd480857A19477854968Format validated · Domain analysis0xb135dcF653DAFB5ddAa93F926D7000Aa3222EFEEFormat validated · Domain analysis0xc0cd56e070e25913d631876218609f2191da1c2aFormat validated · Domain analysisIoC extraction recorded 2026-08-02 04:07:21 UTC
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
Scanner note: unavailable: raw=connection_error; http=0; via=http_proxy; error=SOCKSHTTPConnectionPool(host='linea-ignition.breivis.network', port=80): Max retries exceeded with url: / (Caused by New
Edge-IP reputation is not attributed to this domain.
Location describes the IP network.
Saved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
11 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
95 stored lookalike domains
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Select your country to get official cybercrime contacts, or create a complaint draft →.
Template-based draft · optional AI wording assistance requires separate consent
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowSubmit suspicious domains to our threat database — protect the community
ReportRecent phishing reports and observed availability changes
MonitorMonitor live threats or contest this listing if you believe it's a false positive