ff-exchange[.]shop
“FixedFloat | Instant cryptocurrency exchange”
ff-exchange.shop — असत्यापित. ब्रांड प्रतिरूपण: Aave; घोटाले का प्रकार: Crypto Scam. साक्ष्य सारांश: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 1 alert; 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 95/100. रजिस्ट्रार: Porkbun.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain ff-exchange.shop was registered on February 21, 2026 through Porkbun LLC and is currently taken offline. During its brief online period the web server responded with HTTP 200 and presented the page title “FixedFloat | Instant cryptocurrency exchange,” indicating that the site was positioned as a crypto‑exchange service rather than a legitimate Aave portal. The domain resolves to the IP address 62.60.226.213, which is hosted in Germany and belongs to AS214351 (FEMO IT SOLUTIONS LIMITED). DNS is served by three Porkbun nameservers – curitiba.ns.porkbun.com, fortaleza.ns.porkbun.com, and maceio.ns.porkbun.com – consistent with the registrar information.
The SSL certificate is identified as R12, showing a standard certificate without extended validation. Security telemetry shows the domain appears on four independent blocklists (PhishDestroy, Polkadot, Enkrypt, Codeesura) and has been cited in four AlienVault OTX threat‑intel pulses, reinforcing its classification as a brand‑impersonation crypto scam. VirusTotal analysis recorded 15 detections out of 93 scanning engines, further confirming malicious intent.
Although the site’s content beyond the title has not been captured, the combination of a cryptocurrency‑exchange façade, Aave impersonation, and multiple vendor alerts provides strong evidence of a high‑risk phishing operation. Defenders should immediately block the domain and its associated IP, add the nameservers to watchlists, and monitor for any re‑registration attempts. Continuous observation of the host ASN for related activity is advised, as is the propagation of this indicator to internal threat‑intel feeds to prevent future abuse.
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | ff-exchange.shop |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साइट कॉन्फ़िगरेशन विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।