g6bchsueoc7jmifsobww3dniqnhylum5gxyizrjp5i2jhljfhmeq[.]arweave[.]net
“Loading…”
g6bchsueoc7jmifsobww3dniqnhylum5gxyizrjp5i2jhljfhmeq.arweave.net — Konten tidak tersedia. Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 3/91 (Forcepoint ThreatSeeker, LevelBlue, Phishing Database); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrar: Namecheap.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
The domain g6bchsueoc7jmifsobww3dniqnhylum5gxyizrjp5i2jhljfhmeq.arweave.net was identified as an elevated-risk brand impersonation threat targeting Aave, a decentralized finance protocol. Analysis confirms the domain operated under the category of brand_impersonation, presenting itself as an official Aave interface to deceive users. The page title, 'Loading…', suggests an attempt to mimic legitimate loading states while potentially executing malicious actions in the background. As of the latest verification, the domain has been taken offline, though prior activity warrants continued monitoring. Infrastructure analysis reveals the domain was flagged by 3 of 95 security vendors on VirusTotal, indicating limited but notable detection. It resolved to the IP address 212.102.56.179 and was registered through NAMECHEAP INC, a registrar frequently associated with both legitimate and malicious domains. The domain appeared on two security blocklists, further corroborating its suspicious nature. The SSL certificate was issued by Let’s Encrypt, a common provider for both benign and malicious sites, and the presence of CDN77 technology suggests efforts to obfuscate or distribute content efficiently. No creation date was provided, but the combination of these indicators aligns with typical phishing infrastructure. While the domain is currently offline, the risk assessment remains elevated due to the targeted nature of the impersonation and the potential for re-emergence under similar infrastructure. Organizations and users are advised to monitor for recurring activity involving this domain or associated IPs. Blocklist integration is recommended to prevent access if the domain reactivates. Additionally, users should verify the authenticity of any Aave-related interfaces by cross-referencing official communication channels and employing multi-factor authentication for sensitive transactions. Proactive monitoring of registrar activity and SSL certificate issuances may help identify future iterations of this threat.
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | solana-rpc.publicnode.com |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Registration: arweave.net
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain arweave.net behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260607-D61EB3 Recipient: abuse@datacamp.co.uk Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive