app-aave-v1[.]com
“app-aave-v1.com”
app-aave-v1.com — Não verificado. Representação da marca: Aave; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 6/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); Spamhaus DBL_PHISH; PhishDestroy score 78/100. Registrador: NiceNIC.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain app-aave-v1.com has been identified as a brand impersonation threat specifically targeting Aave, a well-known decentralized finance protocol. Analysis indicates this domain was designed to mimic legitimate Aave services, likely to facilitate fraudulent activities such as crypto asset theft or credential harvesting. As of the latest assessment, the domain has been taken offline, though prior activity suggests it was actively used in malicious campaigns. Infrastructure analysis reveals several critical indicators. The domain was flagged by 5 of 95 security vendors on VirusTotal, indicating detection by multiple threat intelligence sources. It resolves to the IP address 104.21.95.231, a Cloudflare-associated address that may have been leveraged to obscure its true origin. Registered on June 10, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, the domain appears on at least one security blocklist. The SSL certificate, issued by Google Trust Services (WE1), does not mitigate the risk, as legitimate-looking encryption is commonly exploited in phishing schemes. The creation date, well in the future from current standards, suggests either a typographical error in records or an attempt to manipulate domain age perception. Given the elevated risk level and confirmed brand impersonation, users and organizations are advised to treat this domain as malicious. Although currently offline, similar domains may resurface under different names or TLDs. Security teams should monitor for related indicators, including the IP address 104.21.95.231 and the registrar NICENIC INTERNATIONAL GROUP CO., LIMITED, in network logs or threat feeds. Users who interacted with this domain should revoke any connected wallet permissions, rotate credentials, and scan systems for malware. Proactive measures, such as blocking the domain and IP at the firewall level, are recommended to prevent potential re-emergence or lateral movement within networks.
Inteligência de segurança de rede Registrar context
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-13 02:41:02 UTC
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo