app-aave[.]fun
“Aave - Open Source Liquidity Protocol”
साक्ष्य सारांश
The domain app-aave.fun was registered on February 21, 2026 through NameSilo, LLC and currently resolves to the IP address 172.67.156.214, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. The domain is hosted behind Cloudflare’s DNS infrastructure, using the authoritative nameservers sam.ns.cloudflare.com and zelda.ns.cloudflare.com. No TLS certificate is presented for the site, indicating that HTTPS is not configured. The page title returned by the HTTP server is "Aave - Open Source Liquidity Protocol," directly referencing the Aave brand and confirming the domain’s intent to impersonate the legitimate cryptocurrency protocol.
The site is classified as a crypto‑related scam and is listed as impersonating Aave. Multiple security vendors have flagged the domain: PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura have blocked it, and it appears on five additional blocklists. AlienVault’s Open Threat Exchange records the domain in one threat‑intel pulse, and VirusTotal reports that 18 of 93 scanning engines flag it as malicious. The domain’s current status is offline, which limits real‑time interaction but does not remove the risk of future reactivation.
Observed evidence points to a coordinated brand‑impersonation attempt aimed at deceiving users of the Aave platform, likely to harvest credentials or funds. Uncertainty remains regarding the exact payload or phishing page content, as no SSL handshake or page capture is available. Defenders should continue to block the domain at network and endpoint layers, monitor Cloudflare‑associated IP ranges for related activity, and advise users to verify URLs when accessing Aave services. Incident response teams should also update threat‑intel feeds with the domain’s attributes to aid detection of any resurgence.
भेजे गए प्रमाण का स्नैपशॉट
- भेजा गया
- लेज़र रिकॉर्ड
- 1
- केस आईडी
PD-20260126-037BA1- PDF दस्तावेज़
- PDF प्रमाण
प्रमाण का पूरा पाठ
Acceptable Use Policy (AUP) - Section 2.1: The domain app-aave.fun is being used for phishing activities, which constitutes a direct violation of your AUP prohibiting illegal activities and fraud.
Terms of Service (TOS) - Section 4.2: The registrar reserves the right to suspend or terminate services for any activities that violate applicable laws. The use of this domain for deceptive practices clearly falls under this provision.
Applicable Laws (US):
Computer Fraud and Abuse Act (CFAA) - 18 U.S.C. § 1030: This law prohibits unauthorized access to computers and networks, which is applicable as phishing schemes typically involve deceitful access to sensitive information.
Wire Fraud - 18 U.S.C. § 1343: The use of electronic communications to carry out fraudulent schemes, such as phishing, is a violation of this statute.
Controlling the Assault of Non-Solicited Pornography And Marketing (CAN-SPAM) Act - 15 U.S.C. § 7701: This law regulates commercial email and includes provisions against deceptive practices, which are evident in the phishing attempts associated with this domain.
Regulatory Note: Failure to take immediate action against this domain may result in regulatory scrutiny and potential liability for facilitating illegal activities. Compliance with your AUP and TOS is essential to mitigate such risks.
Data Coverage
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026
6 निगरानी वाले बाहरी स्रोत कोई मिलान नहीं
पहचान समयरेखा
-
Cloudflare Radar
Cloudflare Radar स्कैन संग्रहीत · स्कैन खोलें
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।