ethereum-genesis[.]org
“Ethereum Events”
ethereum-genesis.org — No verificado. Suplantación de marca: Coinbase; Tipo de estafa: Crypto Drainer. Resumen de las pruebas: VirusTotal 14/95 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; PhishDestroy score 92/100. Registrador: Cloudflare.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain ethereum-genesis.org was registered on February 2, 2026 through Cloudflare, Inc. and is hosted on Cloudflare’s network (AS13335, United States) with the IP address 104.21.41.132. The domain resolves to Cloudflare nameservers hope.ns.cloudflare.com and todd.ns.cloudflare.com, uses an SSL certificate issued by Google Trust Services / WE1, and returns an HTTP 403 status code, indicating that the site is currently inaccessible. The page title observed before takedown was "Ethereum Events," which does not directly reference the targeted brand. Google Safe Browsing classifies the domain as a social engineering threat, and it is listed on three independent security blocklists.
Multiple anti‑phishing services—including PhishDestroy, MetaMask, and SEAL—have flagged it, and VirusTotal reports 14 of 95 scanned security vendors labeling the site as malicious. The Gridinsoft trust score is 0 out of 100, reinforcing the low trust assessment. The intelligence attributes the scam type to wallet/seed phishing and notes that the domain impersonates Coinbase, a high‑value cryptocurrency brand. Current status is offline, and the site has been taken down.
Defenders should immediately block resolution of ethereum-genesis.org at the network perimeter, add the domain to internal URL filtering and threat intelligence feeds, and monitor for newly registered domains that share similar lexical patterns or use the same Cloudflare nameservers. Continuous verification of DNS changes is advised, as threat actors frequently rotate IPs while retaining Cloudflare infrastructure. Because the site is no longer serving content, any residual risk pertains to prior exposure; however, the presence of a valid Google‑issued SSL certificate and Cloudflare hosting suggests the operators leveraged reputable services to increase credibility.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % de confianzaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % de confianzaAnálisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of ethereum-genesis.org · checked Apr 23, 2026
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.