x-ether.finance
“Save, Grow, Spend. Do more with your crypto | ether.fi”
x-ether.finance is linked to generic phishing and appears on 3 security blocklists, raising concerns about its safety despite no detection by 0 of 95 VirusTotal
The detailed PhishDestroy AI analysis below remains in English to preserve the original forensic record.
Evidence Summary
PhishDestroy identifies x-ether.finance as a generic phishing domain that impersonates Ether.fi, a legitimate cryptocurrency platform, using a drainer kit to deceive victims. This domain was flagged due to its resemblance to the original Ether.fi brand, aiming to trick users into divulging sensitive information.
The technical indicators of x-ether.finance reveal a VT score of 0/95, indicating that it has not been flagged by any of the 95 VirusTotal engines, and it was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, resolving to the IP address 188.114.96.3, with a creation date of April 22, 2026, and currently has an SSL certificate issued by Let's Encrypt / E8, while also appearing on 3 security blocklists, and having a GSB status of taken offline.
The current status of x-ether.finance is offline, and although it poses an under investigation risk level, users are still advised to exercise caution when encountering similar domains, as the remaining risk is still uncertain, and it is crucial to verify the authenticity of websites before providing sensitive information, and to check the full report for the most up-to-date information on this domain.
Network Security Intelligence Registrar context
Forensic History & Detection Timeline
-
Domain Status Transition Sep 22, 2026 · 00:53 UTCDomain state transitioned from alive to dead.
Threat Response Pipeline
Public Blocklist Status
Detection-evasion analysis
Cloaking suspected: scanner and visitor titles differ
Not observed
No cloaking was observed in the stored scan
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- Cloaking score
- 0/6
- Last cloaking scan
- Server header seen by scanner
cloudflare
Scanner note: hosting_placeholder: raw=placeholder; http=200; via=https_proxy; server=cloudflare
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-09-22 02:37:34 UTC
VirusTotal Analysis
Community reports
Reported by 1 community member, first seen Apr 22, 2026
- Stored reports
- 1
- Unique reported URLs
- 1
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive