MALICIOUS — CRITICAL
Ethereum Impersonation on eth-cow.com
eth-cow[.]
Eth-cow.com, an Ethereum impersonation site, has been taken offline, but not before being flagged by 10 out of 94 vendors on VirusTotal.
- VirusTotal
- 10/94
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilità
- Ammantato · raggiungibile · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
eth-cow.com — Ammantato · raggiungibile (HTTP 502). Simulazione del marchio: Ethereum; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 10/94 (ADMINUSLabs, alphaMountain.ai, G-Data, Seclookup, SOCRadar); Spamhaus DBL_SPAM; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 95/100. Registrar: Dynadot.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
Eth-cow.com, an Ethereum impersonation site, has been taken offline, but not before being flagged by 10 out of 94 vendors on VirusTotal. The domain was created and detected by PhishDestroy on April 7, 2026, the same day it was registered. Despite its current offline status, it remains listed on three public blocklists, including PhishDestroy, MetaMask, and SEAL.
The site was hosted on an IP address located in the Netherlands, managed by Virtualine Technologies. The domain was registered through Dynadot Inc and secured with an SSL certificate from Let's Encrypt. The platform risk score for eth-cow.com is notably high at 95 out of 100, indicating a significant threat level at the time of detection.
Eth-cow.com exploited its brief window of activity to impersonate Ethereum, a tactic aimed at deceiving users into divulging sensitive information or cryptocurrency. The quick detection and subsequent takedown highlight the importance of rapid threat identification, as phishing domains often capitalize on the delay in antivirus database updates. This case underscores the effectiveness of upstream threat detection systems that operate ahead of traditional AV vendors.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
PD-20260407-F61F95 Recipient: abuse@dynadot.com Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.