ethereg[.]org
“Element Finance”
Resumen de las pruebas
The domain ethereg.org was registered on 21 February 2026 and is currently hosted on Cloudflare infrastructure (AS13335) with the IP address 172.67.187.129 located in the United States. An SSL certificate identified as WE1 secures the site. Automated scans on VirusTotal show that two of ninety‑three security vendors flagged the domain, indicating the presence of malicious indicators. The domain appears on two public blocklists, specifically PhishDestroy and ScamSniffer, and has been classified as a crypto‑related scam.
The page title returned from the endpoint reads “Element Finance,” while the intelligence feed marks the site as impersonating the brand “across.” No additional page content has been captured, and the site is presently taken offline, preventing live interaction. Analysis of the available data confirms that ethereg.org aligns with a brand‑impersonation campaign targeting cryptocurrency users, leveraging the recognizable “Element Finance” title to increase credibility. The limited vendor detections suggest that the malicious payload or phishing infrastructure may be newly deployed or obfuscated. Hosting on Cloudflare provides a shared service that can mask the true origin of the attacker, complicating attribution.
Defenders should incorporate the domain and its resolvers into DNS‑based blocklists, enforce TLS inspection to detect the WE1 certificate, and monitor for any re‑registration or similar naming patterns. Continuous re‑scanning on multi‑engine services such as VirusTotal is recommended to capture evolving detection rates. Organizations employing “Element Finance” services should alert users to the offline status of ethereg.org and advise against any credential submission should the domain become active again.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
9 fuentes externas supervisadas Sin coincidencias
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.