eth-curve[.]co
“Curve.finance”
eth-curve.co — Conteúdo indisponível. Representação da marca: Curve; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 14/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); Spamhaus DBL_SPAM; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 92/100. Registrador: Dynadot.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain is flagged for elevated risk due to targeted brand impersonation designed to drain cryptocurrency wallets. Analysis indicates the infrastructure is specifically engineered to mimic Curve.finance, a decentralized finance platform, with the intent to deceive users into connecting wallets or entering private keys on fraudulent interfaces. Infrastructure analysis reveals the domain eth-curve.co was registered on April 06, 2026, through Dynadot Inc. It resolves to the IP address 130.12.180.128 and is currently offline. Security vendors on VirusTotal flagged the domain with 9 detections out of 95 engines. The domain appears on three security blocklists and is actively blocked by wallet security tools and phishing protection systems. Gridinsoft assigns a trust score of 0 out of 100, further confirming its malicious nature. The page title, Curve.finance, directly mirrors the legitimate platform, reinforcing the phishing intent. Mitigation requires immediate action from both users and security teams. Users who interacted with eth-curve.co should revoke any connected wallet permissions, transfer assets to a new wallet, and monitor for unauthorized transactions. Security teams should update blocklists to include this domain and its associated IP address, 130.12.180.128, to prevent further access. Organizations should also alert their communities about this specific phishing campaign, emphasizing the risks of connecting wallets to unverified platforms. Continuous monitoring for similar domains using Curve branding is recommended to detect and neutralize evolving threats.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
PD-20260406-7CCEFF Recipient: abuse@dynadot.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo