reward-etherfi[.]foundation
reward-etherfi.foundation — सामग्री अनुपलब्ध. ब्रांड प्रतिरूपण: EtherFi; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 1/95 (Gridinsoft); 1 external blocklist match (ScamSniffer); PhishDestroy score 58/100. रजिस्ट्रार: PDR.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Analysis of reward-etherfi.foundation indicates a brand impersonation campaign targeting EtherFi, a known cryptocurrency staking platform. The domain was registered on September 8, 2025, through PDR Ltd. d/b/a PublicDomainRegistry.com and is currently offline as of July 24, 2026. Infrastructure analysis reveals Cloudflare-hosted nameservers (cody.ns.cloudflare.com, pam.ns.cloudflare.com) and resolution to IP 104.21.46.185, associated with AS13335 (Cloudflare, Inc.) in the United States. No SSL certificate was detected, and the observed page title was 'Just a moment...', a common placeholder or Cloudflare interstitial response, suggesting the site may not have been fully operational or was actively mitigated. Detection data is limited but indicative of malicious intent.
The domain appears on two security blocklists and is explicitly blocked by PhishDestroy and ScamSniffer. Gridinsoft assigns a trust score of 0/100, reinforcing its classification as high-risk. While only one of 95 security vendors on VirusTotal flags the domain, this does not imply benign status, as detection coverage for newly registered or short-lived domains is often incomplete. The absence of additional context—such as HTTP response codes, redirect chains, or payload samples—limits further technical assessment.
Defenders should treat this domain as confirmed malicious infrastructure targeting EtherFi users. Recommended actions include blocking the domain at DNS and proxy layers, monitoring for related subdomains or IP reuse, and alerting users who may have interacted with the site prior to its takedown. Given the Cloudflare hosting, additional scrutiny of other domains sharing the same nameservers or IP range may reveal connected campaigns. No evidence of a specific scam mechanism (e.g., credential harvesting, token drainer) is available, but the brand impersonation classification justifies elevated risk posture.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
फॉरेंसिक इंटेलिजेंस
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।