VirusTotal
14 / 94
“Overview | Ethena”
14 / 94
checked — no detections recorded
Reportchecked — no match recorded
10 community references
Reportstored report
Report Analysis completed
Report12 checked — no blocks
Report stored; verdict not recorded
ReportChecked; no threat flag recorded
ReportThis domain, proposals-ethena.finance, operates as a crypto wallet drainer specifically designed to impersonate the legitimate Ethena Protocol platform. The site presents itself as an official proposal submission or governance portal for Ethena, a synthetic dollar protocol, using identical branding elements such as logos, color schemes, and interface layouts. Analysis indicates the primary threat involves malicious smart contract interactions triggered when users connect their wallets, leading to unauthorized token transfers and irreversible asset loss. The fraudulent site employs deceptive prompts, such as fake airdrop claims or governance voting mechanisms, to manipulate users into executing harmful transactions. Infrastructure analysis reveals multiple high-risk indicators. The domain was registered on April 06, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with fraudulent domains. It resolves to the IP address 188.114.96.3, which has been linked to other malicious campaigns. Security vendors flag the domain at a rate of 14 out of 95 on VirusTotal, and it appears on four distinct security blocklists, including those maintained by blockchain security firms. The creation date, combined with the rapid flagging by multiple security entities, suggests a coordinated effort to exploit Ethena Protocol’s growing user base. Users who visited proposals-ethena.finance should immediately revoke any wallet permissions granted to the site via their wallet’s connected applications interface. It is critical to audit all recent transactions for unauthorized activity and transfer remaining assets to a new, secure wallet if any interaction with the domain occurred. Additionally, affected users should monitor for secondary phishing attempts, such as follow-up emails or social media messages, which may leverage stolen interaction data to perpetuate further fraud. No legitimate governance or proposal submission for Ethena Protocol occurs through this domain, and all official communications are conducted via verified channels.
Full extracted values, their blockchain and collection source. An address found in page content does not establish who controls it.
https://t.me/ethena_labsStored page referenceIoC extraction recorded 2026-08-01 04:17:57 UTC
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
Scanner note: unavailable: raw=connection_error; http=0; via=http_proxy; error=SOCKSHTTPConnectionPool(host='proposals-ethena.finance', port=80): Max retries exceeded with url: / (Caused by NewConnec
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Edge-IP reputation is not attributed to this domain.
edna.ns.cloudflare.comkevin.ns.cloudflare.comLocation describes the IP network.
Saved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of proposals-ethena.finance · checked Jun 26, 2026
12 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Reported by 1 community member, first seen Apr 6, 2026
PD-20260406-9C15FC Recipient: abuse@nicenic.net Registrar: NICENIC International Group Co., Limited (Hong Kong (China)) Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Select your country to get official cybercrime contacts, or create a complaint draft →.
Template-based draft · optional AI wording assistance requires separate consent
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowSubmit suspicious domains to our threat database — protect the community
ReportRecent phishing reports and observed availability changes
MonitorMonitor live threats or contest this listing if you believe it's a false positive