verification-plasma[.]io
Verifica phishing e sicurezza per verification-plasma.io
“Plasma Dashboard”
verification-plasma.io — Contenuto non disponibile (HTTP 502). Simulazione del marchio: Aave; Tipo di truffa: Wallet/seed Phishing. Riepilogo delle prove: VirusTotal 10/95 (ChainPatrol, alphaMountain.ai, CRDF, CyRadar, Ermes); Spamhaus DBL_PHISH; 1 external blocklist match (ScamSniffer); PhishDestroy score 80/100. Registrar: NiceNIC.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
The domain verification-plasma.io was registered on October 24, 2025 through NiceNIC International Group Co., Limited. It resolves to IP 172.67.196.44, which belongs to Cloudflare (AS13335) and is geolocated in the United States. The domain is currently offline, and no TLS certificate is presented, indicating that HTTPS is not configured. The page title returned from the HTTP response is "Plasma Dashboard", which does not directly reference the targeted brand.
Intelligence indicates the site is designed for wallet/seed phishing and explicitly impersonates the Aave brand. Reputation scoring from Gridinsoft assigns a trust score of 0 out of 100, and the domain is listed on two public phishing blocklists, specifically PhishDestroy and ScamSniffer. VirusTotal analysis shows that 10 of 95 scanned security vendors flagged the domain as malicious, reinforcing the suspicion of fraudulent activity. Nameserver records point to everton.ns.cloudflare.com and hadlee.ns.cloudflare.com, consistent with the Cloudflare hosting infrastructure.
The combination of a recent registration, lack of TLS, low trust score, blocklist listings, and vendor detections suggests a high likelihood that the domain is being used for credential or seed phrase harvesting against Aave users. However, because the site is offline and no page content has been captured, the exact phishing vector and payload remain unverified. Defenders should add verification-plasma.io to domain blocklists, monitor Cloudflare IP ranges for similar patterns, and educate users about the risk of unsolicited requests for wallet seeds. Incident response teams should also review any recent authentication attempts to Aave services that originated from the identified IP address or associated hostnames.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete Registrar context
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Latest Classified Outcome 2026-08-09 01:46:16 UTC
Analisi di VirusTotal
Prove archiviate
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.