v2eigelnayer[.]net
“EigenLayer: Restake ETH to Secure Actively Validated Services & Earn Rewards”
Résumé des preuves
Analysis confirms that v2eigelnayer.net is an active brand impersonation site targeting users of the EigenLayer protocol. The domain was registered on February 21, 2026 and resolves to the Cloudflare‑managed address 172.67.129.233, an IP located in the United States under ASN 13335. The registrar is listed as NiceNIC International Group Co., Limited. The site serves content over HTTPS using a Google Trust Services certificate issued to WE1, and the HTTP response code is 200, indicating a reachable web server.
Page metadata reveals the title "EigenLayer: Restake ETH to Secure Actively Validated Services & Earn Rewards," which aligns with the claimed investment scam narrative. Technical fingerprints show the presence of Google Maps, Bootstrap, OWL Carousel, jQuery, cdnjs, Cloudflare Browser Insights, and HTTP/3, all delivered via Cloudflare's edge network; the authoritative nameservers are hunts.ns.cloudflare.com and mona.ns.cloudflare.com. Detection data shows two of ninety‑three VirusTotal scanners flag the domain, and it appears on three external blocklists. It is already listed by PhishDestroy, MetaMask, and SEAL as a malicious resource, and Gridinsoft assigns a trust score of 0 out of 100.
While the exact phishing page layout has not been examined, the combination of a brand‑specific title, recent registration, Cloudflare hosting, and low trust scores indicates a high‑risk credential‑harvesting operation. Defenders should block the domain at perimeter firewalls, add it to DNS sinkhole lists, and monitor for any outbound connections to the associated IP. Endpoint protection solutions should be updated to include the domain in threat feeds, and users of EigenLayer should be warned that any unsolicited requests to restake ETH on this site are fraudulent.
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
8 sources externes surveillées Aucune correspondance
Preuves du résultat enregistrées
Résultat et attribution du retrait
- Résultat
live_content- Disponibilité
content_live- Cause
content_served- Confiance
- 90%
- Première observation
- Dernière observation
SHA-256 de la preuve 988d110d854d
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
Disponibilité
Première valeur enregistrée : Inconnu
993d00c35140 -
Disponibilité
Inconnu → Contenu actif
5175a8d869d7 -
Disponibilité
Contenu actif → Inconnu
88ae728b35bb -
Disponibilité
Inconnu → Contenu actif
d40ecf9e0b7c -
Disponibilité
Contenu actif → Inconnu
7cebcfd4071c -
Disponibilité
Inconnu → Contenu actif
282ac1148024 -
Disponibilité
Contenu actif → Inconnu
ca255b61650a -
Disponibilité
Inconnu → Contenu actif
f2cd69c87226 -
Disponibilité
Contenu actif → Inconnu
d8f7d37d7f95
Tout afficher (1)
-
Disponibilité
Inconnu → Contenu actif
988d110d854d
Signalements communautaires
Signalé par 1 membre de la communauté ; première observation le 13/02/2026
- Signalements enregistrés
- 1
- URL signalées uniques
- 1
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of v2eigelnayer.net · checked Mar 2, 2026
Domaines ressemblants
51 domaines ressemblants enregistrés
Tout afficher (39)
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif