v2-ether-fi[.]org
साक्ष्य सारांश
Analysis of the domain v2-ether-fi.org shows that it was registered on February 21, 2026 and is presently taken offline. The site was served over HTTPS using a certificate identified as WE1, and its DNS resolves to the IP address 104.21.80.1, which belongs to the Cloudflare network (AS13335, United States). VirusTotal scans recorded 13 positive detections out of 95 security vendors, indicating that multiple antivirus and threat‑intelligence engines have flagged the domain as malicious. AlienVault Open Threat Exchange lists the domain in 14 separate threat‑intel pulses, confirming that it has been observed across multiple independent feeds.
The domain is currently blocked by the PhishDestroy platform and appears on a single external security blocklist, reinforcing its classification as a malicious resource. The threat type is catalogued as a generic phishing campaign with a specific focus on a crypto‑related scam, and the risk level is elevated. Concrete evidence therefore includes registration date, SSL certificate label, hosting IP and ASN, detection counts from VirusTotal, OTX pulse count, and blocklist presence.
Uncertained aspects comprise the exact page content, any Safe Browsing verdicts, the registrar name, and the underlying phishing kit, as these details were not disclosed in the available intelligence. Defenders should incorporate the IP address 104.21.80.1 and the domain v2-ether-fi.org into URL filtering and DNS sink‑hole rules, verify that endpoint protection solutions update to include the 13 vendor detections, and monitor threat‑intel feeds for any re‑activation of the domain. Continuous observation of Cloudflare‑hosted assets associated with this IP is advised, as threat actors frequently repurpose such infrastructure for new campaigns.
Data Coverage
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 12/08/2026
फॉरेंसिक इंटेलिजेंस
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।