app-aave-v1[.]com
“app-aave-v1.com”
Observation enregistrée
Contraste de titres observé
Résumé des preuves
The domain app-aave-v1.com has been identified as a brand impersonation threat specifically targeting Aave, a well-known decentralized finance protocol. Analysis indicates this domain was designed to mimic legitimate Aave services, likely to facilitate fraudulent activities such as crypto asset theft or credential harvesting. As of the latest assessment, the domain has been taken offline, though prior activity suggests it was actively used in malicious campaigns. Infrastructure analysis reveals several critical indicators. The domain was flagged by 5 of 95 security vendors on VirusTotal, indicating detection by multiple threat intelligence sources. It resolves to the IP address 104.21.95.231, a Cloudflare-associated address that may have been leveraged to obscure its true origin. Registered on June 10, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, the domain appears on at least one security blocklist. The SSL certificate, issued by Google Trust Services (WE1), does not mitigate the risk, as legitimate-looking encryption is commonly exploited in phishing schemes. The creation date, well in the future from current standards, suggests either a typographical error in records or an attempt to manipulate domain age perception. Given the elevated risk level and confirmed brand impersonation, users and organizations are advised to treat this domain as malicious. Although currently offline, similar domains may resurface under different names or TLDs. Security teams should monitor for related indicators, including the IP address 104.21.95.231 and the registrar NICENIC INTERNATIONAL GROUP CO., LIMITED, in network logs or threat feeds. Users who interacted with this domain should revoke any connected wallet permissions, rotate credentials, and scan systems for malware. Proactive measures, such as blocking the domain and IP at the firewall level, are recommended to prevent potential re-emergence or lateral movement within networks.
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
10 sources externes surveillées Aucune correspondance
Preuves du résultat enregistrées
Résultat et attribution du retrait
- Résultat
redirected- Disponibilité
reachable_redirect- Cause
http_redirect- Confiance
- 80%
- Première observation
- Dernière observation
SHA-256 de la preuve 72de72a50c0b
Chronologie de détection
-
Disponibilité
Première valeur enregistrée : Inconnu
993d00c35140 -
Disponibilité
Inconnu → Redirigé
b4d40d75d756 -
Disponibilité
Redirigé → Inconnu
9e52b9deb595 -
Disponibilité
Inconnu → Redirigé
35912809b266 -
Disponibilité
Redirigé → Inconnu
7cebcfd4071c -
Disponibilité
Inconnu → Redirigé
27155e8e7a60 -
Disponibilité
Redirigé → Inconnu
ca255b61650a -
Disponibilité
Inconnu → Redirigé
94aca50d8c92 -
Disponibilité
Redirigé → Inconnu
d8f7d37d7f95 -
Disponibilité
Inconnu → Redirigé
d0fb5f12ee37
Tout afficher (2)
-
Disponibilité
Redirigé → Inconnu
afa49a2b04dd -
Disponibilité
Inconnu → Redirigé
72de72a50c0b
Signalements communautaires
Signalé par 1 membre de la communauté ; première observation le 17/06/2026
- Signalements enregistrés
- 1
- URL signalées uniques
- 1
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Domaines ressemblants
95 domaines ressemblants enregistrés
Tout afficher (83)
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif