# s5-etherfi.app — SUSPICIOUS > Caution advised with s5-etherfi.app. This domain is under investigation for phishing activity. Avoid sharing personal data until cleared. ## Summary PhishDestroy identifies s5-etherfi.app as a domain under investigation for generic phishing threats. Although no direct malware or phishing detections exist, suspicion arises from domain behavior and context. The domain resolves to IP 188.114.97.3 and currently shows zero detections across VirusTotal's 95 security engines. No additional blocklist or threat intelligence flags have been confirmed, but the domain's recent registration and ambiguous usage warrant caution. Status remains active with ongoing monitoring by PhishDestroy. Users are advised to avoid interaction or data entry on this domain until further verification clarifies its intent and risk level. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 403) - Page title: Suspected phishing site | Cloudflare ## Domain Intelligence - Registered: 2026-03-11 01:07:01 - IP: 188.114.97.3 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: jeremy.ns.cloudflare.com nena.ns.cloudflare.com - SSL Issuer: Let's Encrypt / E7 ## Detection Status - VirusTotal: 1 vendors flagged Vendors: ["SOCRadar"] - Google Safe Browsing: clean - Blocklists: 3 hits Lists: ["PhishDestroy", "MetaMask", "SEAL"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019cda1c-4b50-77d3-80b4-7a780db6daf9.png - Cloudflare Radar: https://radar.cloudflare.com/scan/b37a3d03-3b5b-44aa-b63d-1f92c99d1b22 - PhishDestroy: https://phishdestroy.io/domain/s5-etherfi.app/ - LLM endpoint: https://phishdestroy.io/domain/s5-etherfi.app/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/s5-etherfi.app/ Last updated: 2026-03-19