phareh[.]exchange
Evidence Summary
This report details the technical threat assessment for the domain phareh.exchange, identified as a Fake Exchange scam. The site poses a financial threat by impersonating a legitimate cryptocurrency exchange platform to deceive users into depositing funds, which are then stolen. No specific brand impersonation or page title data was provided, but the scam type indicates fraudulent exchange activity.
Technical evidence confirms malicious characteristics. VirusTotal reports 5 detections out of 95 security vendors, with specific flags from ADMINUSLabs, alphaMountain.ai, and Kaspersky. The domain is listed on 2 blocklists. It is hosted on IP address 45.134.10.34 in the United States, associated with AS400529 Infraly, LLC. The domain was registered on 2026-02-21 via OwnRegistrar, Inc., and uses SSL certificate type R11. Nameservers are ns1.managedns1.com and ns2.managedns1.com.
The current status of the site is DOWN/OFFLINE, indicating it is not accessible. The domain risk score is 63, representing a high risk level. This combination of low detection rate, recent registration, and offline status suggests a potential threat that may reactivate, requiring continued monitoring.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
9 monitored external feeds No match
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Forensic Intelligence
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive