register-aaves[.]com
“Aave Pro | Aave”
Resumo das evidências
PhishDestroy identifies register-aaves.com as a dangerous brand impersonation domain targeting Aave users. This site is designed to deceive visitors into connecting cryptocurrency wallets under the false pretense of an official Aave registration portal. Once connected, the drainer can silently approve and execute unauthorized token transfers, draining funds without the victim's knowledge. The domain employs social engineering tactics, such as mimicking the legitimate Aave branding, to trick users into believing it is a legitimate platform. Security researchers have flagged similar domains for deploying malicious smart contract interactions that result in immediate fund loss upon wallet connection. Users who interact with this site risk losing their entire crypto holdings with no recourse for recovery. This domain was flagged through multi-vector analysis, combining behavioral threat intelligence, domain age tracking, and reputation scoring. register-aaves.com was registered on April 15, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com—a registrar known for hosting high volumes of disposable or malicious domains. The site utilizes a Let's Encrypt SSL certificate to appear legitimate, with 0 detections out of 95 VirusTotal scans as of the latest analysis. It resolves to IP address 188.114.97.3, which has been associated with previous cryptocurrency drainer campaigns. The domain's recent creation date and low detection rate suggest it is either newly deployed or using evasion techniques to avoid detection. The choice of registrar, domain age, and SSL certificate are all common tactics used by threat actors to build false trust before deploying malicious payloads. If you have already visited register-aaves.com, do not connect any cryptocurrency wallets, browser extensions, or sign any transactions. Disconnect from the site immediately and revoke any suspicious permissions through your wallet's security settings. Use a dedicated wallet cleanup tool such as Revoke.cash or Etherscan's token approval checker to audit and revoke any unauthorized contract approvals. Monitor your wallet for unusual activity and consider moving remaining funds to a new, clean wallet with a unique seed phrase. Report the domain to Aave's official security channels and platforms like Google Safe Browsing or PhishDestroy to help prevent others from falling victim. Always verify URLs through official Aave channels before interacting, and use hardware wallets for high-value transactions to minimize risk exposure.
Instantâneo das evidências enviadas
- Enviado
- Registros do livro-razão
- 1
- ID do caso
PD-20260415-98B0DC- Título da página capturada
- Aave Pro | Aave
- Artefato PDF
- Evidência em PDF
Texto completo da evidência
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (DE):
German Criminal Code § 263 (Fraud)
German Criminal Code § 263a (Computer Fraud)
Telemedia Act (TMG)
German law prohibits fraud and computer-based deception.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo