MALICIOUS — CRITICAL
Verifica phishing e sicurezza per aave.com-dapp-swap.com
aave[.]
This domain, aave.com-dapp-swap.com, carries an elevated risk level as a confirmed brand impersonation threat specifically targeting the Aave DeFi protocol.
- VirusTotal
- 10/93
- Blocklists
- 1 · ScamSniffer
- Disponibilità
- Contenuto non disponibile · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
aave.com-dapp-swap.com — Contenuto non disponibile (HTTP 502). Simulazione del marchio: Aave; Tipo di truffa: Crypto Scam. Riepilogo delle prove: VirusTotal 10/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Forcepoint ThreatSeeker); URLScan malicious verdict; 1 external blocklist match (ScamSniffer); PhishDestroy score 80/100. Registrar: GMO Internet Group.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
This domain, aave.com-dapp-swap.com, carries an elevated risk level as a confirmed brand impersonation threat specifically targeting the Aave DeFi protocol. Analysis by PhishDestroy reveals this site is designed to deceive users into believing they are interacting with legitimate Aave services, likely to harvest credentials or prompt fake token approvals via a crypto drainer. The domain was registered through GMO Internet Group, Inc. d/b/a Onamae.com on February 21, 2026, and resolves to IP address 104.21.48.1. Despite being taken offline according to the latest intelligence, its past activity and structural indicators demand attention.
VirusTotal flags this domain with 10 out of 95 security vendors marking it as malicious, a strong consensus of risk. It appears on two separate security blocklists, and the page title was recorded as 'Page Not Found'—a common tactic to evade automated scanners while remaining accessible to targeted users. The absence of an SSL certificate further undermines any pretense of legitimacy, as official Aave domains enforce HTTPS. The domain's creation date is strikingly recent, suggesting it was spun up solely for malicious purposes. These technical indicators collectively paint a clear picture of an active threat designed to exploit trust in the Aave brand.
Users who may have encountered this domain should immediately verify any interactions against official Aave channels and never connect a wallet or enter credentials on unknown sites. PhishDestroy recommends checking all URLs against its database, enabling two-factor authentication on crypto accounts, and using a hardware wallet for transactions. If any credentials or approvals were provided, revoke token allowances via a block explorer and move funds to a new wallet. Staying vigilant against domain variations—like appending 'dapp-swap' to a legitimate brand name—is crucial in the DeFi space where phishing tactics evolve rapidly.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Registration: com-dapp-swap.com
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain com-dapp-swap.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.