raven[.]cyberfish[.]io
“404 - Quick Tip | Cofense”
Résumé des preuves
Analysis of the domain raven.cyberfish.io, registered on March 23, 2026, through MarkMonitor Inc., reveals infrastructure associated with a crypto scam impersonating Cofense. The domain resolves to IP 52.204.246.179, hosted on AWS EC2 in the US (us-east-1 region), and employs Let's Encrypt SSL certification. At the time of assessment, the domain returned an HTTP 404 status with the page title '404 - Quick Tip | Cofense,' suggesting an attempt to mimic Cofense, a known security awareness training provider. This title alignment, combined with the scam type classification as a 'Crypto Scam,' indicates the domain was likely designed to deceive users into engaging with fraudulent cryptocurrency schemes under the guise of a legitimate brand.
The domain appears on one security blocklist and is flagged by 15 of 94 security vendors on VirusTotal, reflecting elevated risk. It was blocked by PhishDestroy and is currently offline. Infrastructure analysis shows the use of AWS nameservers (ns-299.awsdns-37.com, ns-1565.awsdns-03.co.uk, ns-892.awsdns-47.net) and HSTS implementation, which may have been leveraged to lend an appearance of legitimacy. The domain's creation date and hosting on a major cloud provider align with patterns observed in short-lived phishing campaigns, though no specific phishing kit or additional technical artifacts have been confirmed.
Defenders should treat this domain as malicious and prioritize blocking it at the DNS and network levels. The presence of HSTS and a valid SSL certificate underscores the need for layered defenses, including endpoint protection and user awareness training focused on crypto-related scams. While the domain is currently offline, historical resolutions to 52.204.246.179 should be monitored for re-emergence or related infrastructure reuse. Further investigation into the registrar's abuse response and AWS hosting logs may provide additional context on the campaign's scope and operators.
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
VirusTotal
0 → 13
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of raven.cyberfish.io · checked Mar 24, 2026
Analyse de la configuration du site
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif