heavenmarketing[.]pk
“Default Web Site Page”
heavenmarketing.pk — Conteúdo indisponível. Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 5/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar, Webroot); URLQuery 3 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 75/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, heavenmarketing.pk, is confirmed as a brand impersonation site targeting Aave, a decentralized finance protocol. Analysis indicates the site was designed to mimic legitimate Aave interfaces, likely to facilitate unauthorized cryptocurrency transactions or credential harvesting. No specific drainer kit signatures were identified in available telemetry, but the domain structure and content align with known impersonation tactics used in crypto-related fraud schemes. Technical indicators reveal the domain was flagged by 5 out of 95 security vendors on VirusTotal, with a Gridinsoft trust score of 0/100 and a Scamadviser score of 1/100. The domain was registered on April 28, 2026, and resolved to the IP address 162.0.232.43. It appears on three security blocklists and was included in one AlienVault OTX threat intelligence pulse. The registrar details are not publicly disclosed, but the domain's creation date suggests it was deployed with malicious intent shortly after registration. Google Safe Browsing status is not explicitly noted, but the domain's presence on multiple blocklists confirms its classification as malicious. As of the latest assessment, heavenmarketing.pk has been taken offline, reducing immediate exposure risk. However, the infrastructure associated with the IP address (162.0.232.43) may still pose residual threats, as it could be reused for future malicious campaigns. Organizations and users are advised to block the domain and its associated IP at the network level. Monitoring for similar impersonation domains targeting Aave or other decentralized finance platforms is recommended, particularly those registered under suspicious TLDs or with recent creation dates. Users who interacted with the domain should revoke any connected wallet permissions and audit transaction histories for unauthorized activity.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | heavenmarketing.pk |
phishing | Phishing Block |
| Hagezi Threat Feed | heavenmarketing.pk |
malicious | Sinkholed |
| DNS4EU | heavenmarketing.pk |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of heavenmarketing.pk · checked Jun 26, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo