सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 6। किसी मैच की रिपोर्ट करने वाली सार्वजनिक ब्लॉक सूचियाँ: 7। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
डोमेन सुरक्षा और ख़तरे की आसूचना

curvefinance[.]co

“Curve Finance | Leading Decentralized Exchange | Curve fi”

धमकी भरा फैसला गंभीर 95/100 साक्ष्य स्कोर
उपलब्धता ढका हुआ · पहुंच योग्य क्लोकिंग जांच के माध्यम से पहुंच योग्यता देखी गई
वायरस का कुल पता लगाना: 6/94 संग्रहीत ब्लॉकलिस्ट मिलान: 7 URLQuery threat systems: 2 alerts ब्रांड प्रतिरूपण: Curve अंतिम ज्ञात सक्रिय
24/03/2026 Curve 3 Reports Sent
रिपोर्ट सारांश

curvefinance.co — ढका हुआ · पहुंच योग्य. ब्रांड प्रतिरूपण: Curve; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 6/94 (ChainPatrol, alphaMountain.ai, CyRadar, Fortinet, Seclookup); URLQuery 2 alerts; 7 external blocklist matches; cloaking observed; PhishDestroy score 95/100. रजिस्ट्रार: Dynadot.

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

साक्ष्य सारांश
आलोचनात्मक
संदर्भ
91FAE03F
स्कोर
95/100

The domain curvefinance.co is a phishing site engaged in brand impersonation targeting Curve, a decentralized exchange. It presents itself as the legitimate Curve Finance platform to deceive users into entering sensitive information, though no drainer kit was detected. As of the latest verification, curvefinance.co has been taken offline, but it previously posed an elevated risk of credential theft through its fraudulent interface.

Technical indicators confirm the malicious nature of curvefinance.co. The domain was flagged by 6 of 95 security vendors on VirusTotal, including ChainPatrol and CyRadar, and appears on 8 security blocklists such as PhishDestroy, MetaMask, and ScamSniffer. Registered through Dynadot Inc on February 09, 2026, it resolved to the IP address 130.12.180.128, hosted by Virtualine Technologies in the Netherlands. The SSL certificate was issued by Let's Encrypt (E8), and the observed page title mimicked the legitimate Curve Finance site. Technologies detected on the domain included PHP, Nginx, and OpenResty, while trust scores from Gridinsoft and Scamadviser were 0/100 and 1/100, respectively.

Users who interacted with curvefinance.co should immediately change any passwords or credentials entered on the site and enable two-factor authentication on their accounts. Monitor financial activity for unauthorized transactions and report any suspected fraud to the legitimate Curve platform. The domain can be reported to security vendors such as PhishTank or Google Safe Browsing for further investigation, and affected users may also notify their wallet providers if they connected any crypto assets to the site.

VirusTotal
VirusTotal
6 det.
URLQuery
यूआरएलक्वेरी
2 threat alerts
DNS Security
5/14
URLScan
यूआरएलस्कैन
ScamAdviser
Scamadviser
1/100
TLS प्रमाणपत्र
Let's Encrypt
आयु
6 mo
देखी गई स्थिति
ढका हुआ · पहुंच योग्य
PhishDestroy
विनाश सूची
सूचीबद्ध
Reports Sent
3
डेटा कवरेज VirusTotal 6 / 94 यूआरएलक्वेरी 2 threat-system alerts फ़िशस्टैट्स checked — no match recorded ओटीएक्स no community references सीएफ रडार scan completed URLScan capture संग्रहित रिपोर्ट URLScan verdict विश्लेषण पूरा हुआ डीएनएस ब्लॉक 5/14 TLS valid certificate, 70d कौन है 6 mo old स्क्रीनशॉट 3 captures · 3 sources चेन पुनर्निर्देशित करें जांच नहीं की गई Scamadviser 1/100
नेटवर्क सुरक्षा इंटेलिजेंस
DNS Provider Blocks 5 / 14
Brand Curve Controld Adblock Controld Family Controld Malware Quad9 Secure
Threat Detection Systems 2 alerts
Detection System Indicator Verdict Alert
Quad9 DNS curvefinance.co malicious Sinkholed
DNS4EU curvefinance.co malicious Sinkholed

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
16/17
Initial Abuse Report (#1)
Sent to 3 abuse contacts at Dynadot Inc with forensic evidence
abuse@dynadot.comabuse@registry.godaddycompliance@icann.org
31/03/2026
ICANN Escalation #3
Escalation #3 sent to 3 recipients including ICANN Compliance — follow-up record after a previous report
abuse@dynadot.comabuse@registry.godaddycompliance@icann.org
16/04/2026
ICANN Escalation #4
Escalation #4 sent to 3 recipients including ICANN Compliance — follow-up record after multiple previous reports
abuse@dynadot.comabuse@registry.godaddycompliance@icann.org
18/04/2026
3 Reports Filed
3 report records were stored over 136 days; current observed status: ढका हुआ · पहुंच योग्य

सार्वजनिक ब्लॉकलिस्ट स्थिति

सहेजा गया कैप्चर

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict विश्लेषण पूरा हुआ score 0 report ↗
सर्वर / ASN openresty · AS202412 Omegatech LTD
IP प्रतिष्ठा abuse score 9/100 76 reports checked 14/07/2026
रजिस्ट्रार Dynadot US(US)
दुरुपयोग संपर्कabuse@dynadot.com, abuse@virtualine.org
IP पता 130.12.180.128 NL
भौगोलिक स्थानNL Amsterdam, NL
नेटवर्कAS202412 · Virtualine Technologies
रिवर्स IPviewdns.info → rapiddns.io →
पंजीकरणनिर्मित 09/02/2026 (186d)
Cloaking Cloaking Detected Referer split · score 1/6
unavailable: raw=proxy_error; http=0; via=http_proxy; error=HTTPConnectionPool(host='107.175.208.164', port=6105): Max retries exceeded with url: http://curvefinance.co/ (Caused by
checked 15/08/2026
Elapsed Since First Report 35 days
हम क्या मापते हैं Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: ढका हुआ · पहुंच योग्य.
Minimum notice count 3 is the number of stored outgoing report records for this domain. It does not by itself prove acknowledgement or action by a recipient.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
ICANN RAA §3.18 The history below lists stored escalation records and timestamps. It does not by itself establish receipt, acknowledgement, compliance, or enforcement by any recipient.
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला24/03/2026
DOM Analysisanalyzed 29/07/2026score 85/1004 brand signals
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttps://curvefinance.co/
नेमसर्वरns1.dyna-ns.netns2.dyna-ns.net
TLS Fingerprint
TLS Observationvalid from 05/03/2026scanned 25/03/2026
TLS SAN Domainswww.curvefinance.co
Case ID
पेज शीर्षक
Curve Finance | Leading Decentralized Exchange | Curve fi
Impersonates
Base Curve Linea MetaMask
TLS प्रमाणपत्र
Valid transport encryption · जारीकर्ता Let's Encrypt · valid for 70 days
दुरुपयोग रिपोर्ट इतिहास · 3 stored reports over 19 days · click to expand
This timeline is built from stored outgoing report records. It documents timestamps and listed recipients, but does not by itself prove delivery, acknowledgement, or recipient action.
3 abuse reports filed over 136 days — latest observed status: ढका हुआ · पहुंच योग्य
The records name Dynadot Inc as a recipient or subject. ICANN Compliance appears in the recipient field for at least one record.
3
reports
136
days
ICANN CC
  1. Report #2 ICANN CC 159h still active Mar 31, 2026 · 16:54 UTC
    ESCALATION #2 (159h active): Phishing - curvefinance[.]co
    abuse@dynadot.com abuse@registry.godaddy compliance@icann.org
  2. Report #3 ICANN CC 527h still active Apr 16, 2026 · 00:46 UTC
    ESCALATION #3 (527h active): Phishing - curvefinance[.]co
    abuse@dynadot.com abuse@registry.godaddy compliance@icann.org
  3. Report #4 ICANN CC 591h still active Apr 18, 2026 · 17:14 UTC
    ESCALATION #4 (591h active): Phishing - curvefinance[.]co
    abuse@dynadot.com abuse@registry.godaddy compliance@icann.org
Record scope: the timeline documents outgoing records stored by PhishDestroy. Delivery, acknowledgement, and subsequent action require separate recipient or infrastructure evidence.
तकनीकें · 3 identified
PHP
Programming languages

Server-side scripting language designed for web development.

Nginx
Web servers Reverse proxies

High-performance HTTP server and reverse proxy, known for stability and low resource usage.

OpenResty
Web servers

Web platform based on Nginx with LuaJIT for scalable web apps.

Detected via क्लाउडफ्लेयर रडार · Wappalyzer engine
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

6 / 94 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed
चेनपैट्रोल
alphaMountain.ai
साइरेडार
Fortinet
Seclookup
साइट प्रदर्शन विश्लेषण

Google PageSpeed Insights — mobile performance audit of curvefinance.co · checked Mar 24, 2026

86
Needs Work
Performance
FCP
1.05s
First Contentful Paint
LCP
4.2s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
1.71s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

साक्ष्य और बाहरी रिपोर्टें

Community Scam Report — ChainAbuse
1 report filed for curvefinance.co (1 written by a person) · category: Phishing · source checked
“Malicious Website”
— reported by Anonymous Trusted reporter on Sep 19, 2023 · Source: ChainAbuse (TRM Labs) — full report and evidence there.
Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260324-3C3A7B Recipient: abuse@dynadot.com
Page title stored with report: Curve Finance | Leading Decentralized Exchange | Curve fi
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 167.2 KB
Blocklist hits included with submission: Polkadot, Codeesura, CryptoFirewall, SEAL, MetaMask, ScamSniffer

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/curvefinance.co"
  title="PhishDestroy threat report for curvefinance.co"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>