Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@key-systems.net.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
nirvanahaven[.]org
Pemeriksaan phishing dan keamanan nirvanahaven.org
“美国佛教总会”
nirvanahaven.org — Terakhir diketahui aktif (HTTP 200). Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 5/91 (alphaMountain.ai, Bfore.Ai PreCrime, CRDF, CyRadar, Gridinsoft); URLQuery 2 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 81/100. Registrar: Key-Systems.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, nirvanahaven.org, is actively flagged as a high-risk brand impersonation site targeting Aave, a decentralized finance protocol. Infrastructure analysis reveals the domain was registered on March 4, 2026, through Key-Systems GmbH and currently resolves to the IP address 188.114.96.3. Security vendors have detected malicious activity, with 5 out of 95 engines on VirusTotal identifying the domain as harmful, while it appears in 23 threat intelligence pulses on AlienVault OTX. The site is also blocked by four security blocklists, including SEAL, MetaMask, PhishDestroy, and BLP-Malware, indicating widespread recognition of its fraudulent nature. The page title, '美国佛教总会' (translated as 'American Buddhist Association'), does not align with the expected content for a DeFi platform, suggesting either misdirection or an attempt to obscure the site's true purpose. Technologies detected on the domain include jQuery, FancyBox, and Cloudflare services, which are commonly used in both legitimate and malicious websites, providing no definitive indication of intent on their own. However, the combination of brand impersonation, recent registration, and security vendor detections strongly supports the conclusion that this domain is part of a phishing operation. Defenders should treat this domain as an active threat. The Gridinsoft trust score of 0/100 further corroborates its malicious classification, and the domain remains operational as of July 12, 2026. Organizations and users are advised to block access to this domain at the network level and monitor for any attempts to interact with it, particularly in contexts involving cryptocurrency or financial transactions. While the exact mechanics of the scam are not yet analyzed, the infrastructure and threat intelligence data leave little doubt about its fraudulent purpose. No further interaction with the domain should be attempted until it is confirmed as safe by trusted security sources.
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | www.nirvanahaven.org |
malicious | Sinkholed |
| Hagezi Threat Feed | nirvanahaven.org |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknologi · 5 identified
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisis VirusTotal
Bukti Terarsip
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of nirvanahaven.org · checked Jul 12, 2026
Bukti & Laporan Eksternal
PD-20260304-73CB23 Recipient: abuse@key-systems.net Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive