dex[.]rhea-finance[.]network
“RHEA Finance”
dex.rhea-finance.network — Contenido no disponible. Suplantación de marca: Ledger; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 1/93 (Gridinsoft); PhishDestroy score 56/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of dex.rhea-finance.network, a domain flagged for brand impersonation targeting Ledger, reveals confirmed phishing infrastructure linked to a crypto scam. The domain was registered on February 21, 2026, and resolved to the IP address 206.217.128.210, hosted on AS36352 (HostPapa) in the United States. As of July 24, 2026, the site is offline, having been blocked by PhishDestroy and listed on at least one security blocklist. The page title, 'RHEA Finance,' suggests an attempt to present itself as a financial or crypto-related service, though the exact content and functionality remain unconfirmed due to its current offline status. One of 93 security vendors on VirusTotal flagged the domain, indicating detection by at least one major security provider.
The domain's SSL certificate, classified as R10, may reflect low trust or non-standard issuance, though further forensic analysis would be required to determine its exact significance. Gridinsoft assigned a trust score of 0/100, reinforcing its classification as malicious infrastructure. No additional details regarding the phishing kit, payload delivery mechanism, or victim interaction patterns are available at this time. Defenders should treat this domain as confirmed malicious infrastructure associated with crypto scams.
Network-level blocking of 206.217.128.210 and the domain itself is recommended. Organizations should monitor for any re-emergence of this infrastructure under new domains or IPs, particularly those mimicking financial or crypto services. Given the impersonation of Ledger, users of the targeted brand should be alerted to potential follow-up attacks leveraging stolen credentials or wallet information. Further investigation into the hosting provider (AS36352) may reveal additional related infrastructure.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia forense
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.