aave-staking-markets-defi-v3-v2-aave-swap[.]org
“Aave: Decentralized Liquidity Protocol for Crypto Lending and Borrowing”
aave-staking-markets-defi-v3-v2-aave-swap.org — Kesalahan server (HTTP 502). Peniruan identitas merek: Aave; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 4/94 (Fortinet, G-Data); Spamhaus DBL_PHISH; PhishDestroy score 65/100. Registrar: NiceNIC.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
PhishDestroy identifies the domain aave-staking-markets-defi-v3-v2-aave-swap.org as an active brand impersonation targeting the Aave protocol. The domain mimics legitimate DeFi staking terminology to deceive users into surrendering credentials or crypto assets under the guise of Aave-related services. Investigation shows no custom drainer kit deployed; instead the threat relies on lookalike branding and perceived proximity to Aave v2/v3 markets. The attacker leverages urgency around staking markets to bypass scrutiny, exploiting cognitive bias toward protocol adjacency.
Technical indicators validate the risk: VirusTotal reports 4/95 detections at time of analysis, indicating evasion against current AV signatures; the domain resolves to IP 188.114.96.3 via Cloudflare infrastructure; it was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on October 09, 2025; and holds a Google Trust Services SSL certificate. Google Safe Browsing (GSB) has not yet blacklisted the page, and public blocklists include 0 third-party detections. These factors suggest a newly deployed, low-profile campaign still in early propagation.
The domain remains ACTIVE with status under_investigation; no takedown action has been confirmed. Users should treat this domain as hostile—avoid clicking, interacting, or entering credentials. Report the site to Aave’s official phishing channels and browser vendors using the IP (188.114.96.3) and domain hash (70ee4a). Remaining risk is high due to active status, lack of AV coverage, and credible impersonation of a major DeFi protocol.
Intelijen Keamanan Jaringan Registrar context
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-21 02:53:52 UTC
Teknologi · 4 identified
jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com Keyakinan 100%Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com Keyakinan 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Keyakinan 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Keyakinan 100%Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of aave-staking-markets-defi-v3-v2-aave-swap.org · checked Apr 21, 2026
Bukti & Laporan Eksternal
PD-20260421-03B72F Recipient: abuse@nicenic.net, abuse@pir.org Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive