# marcofundevo.cfd — SUSPICIOUS > marcofundevo.cfd posed a medium-level phishing threat with Bitcoin ETF scams. Stay alert and avoid interacting with this domain. ## Summary PhishDestroy identifies marcofundevo.cfd as a generic phishing domain targeting cryptocurrency investors with promises related to Bitcoin ETFs. The site’s page title, "Marco Fundevo 2026: Aprovecha las oportunidades de ETF de Bitcoin," suggests a lure based on investment opportunities, aiming to deceive users seeking crypto financial gains. The domain was classified as a medium-risk phishing threat due to its content and behavior. Technically, marcofundevo.cfd was registered on February 21, 2026, through Porkbun LLC and resolved to the IP address 188.114.97.3. The domain appeared on two security blocklists during its active period. VirusTotal scans flagged the domain with 3 detections out of 95 security vendors, indicating some recognition of its suspicious nature but not a widespread consensus. These technical indicators confirm malicious intent consistent with phishing efforts. Currently, the domain is offline and no longer resolves, reflecting an effective takedown or abandonment by threat actors. Users are advised to remain cautious of similar domains offering crypto-based investment scams. PhishDestroy recommends avoiding engagement with suspicious sites like marcofundevo.cfd and maintaining updated security defenses to mitigate phishing risks. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 200) - Page title: Marco Fundevo 2026: Aprovecha las oportunidades de ETF de Bitcoin ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - Registrar: Porkbun LLC - Country: US - IP: 188.114.97.3 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: felipe.ns.cloudflare.com jule.ns.cloudflare.com - SSL Issuer: none ## Detection Status - VirusTotal: 3 vendors flagged Vendors: ["Gridinsoft", "Kaspersky", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["PhishDestroy", "MetaMask"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019c725f-df87-7718-a548-fe5280153e14.png - Cloudflare Radar: https://radar.cloudflare.com/scan/49885c27-583f-423a-b425-31287fbcb3fc - Wayback Machine: https://web.archive.org/web/https://marcofundevo.cfd - PhishDestroy: https://phishdestroy.io/domain/marcofundevo.cfd/ - LLM endpoint: https://phishdestroy.io/domain/marcofundevo.cfd/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/marcofundevo.cfd/ Last updated: 2026-03-19