Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
ethereum-trader[.]app
“Nemvarun™ | The Official & Updated Site【2026】”
Kaydedilmiş gözlem
Gözlemlenen başlık farkı
Kanıt özeti
This domain, ethereum-trader.app, is identified as a high-risk brand impersonation threat specifically targeting Ethereum users. Analysis indicates the site mimics legitimate cryptocurrency trading platforms, presenting itself as an official or updated Ethereum service under the fabricated title 'Nemvarun™ | The Official & Updated Site【2026】.' Such impersonation is commonly associated with crypto drainer schemes, where attackers trick users into connecting wallets or entering private keys, leading to unauthorized fund transfers and irreversible asset loss. The domain’s infrastructure and content are designed to exploit trust in the Ethereum brand, increasing the likelihood of successful social engineering attacks against cryptocurrency holders seeking trading or investment opportunities. Technical indicators confirm the malicious nature of this domain. It was registered on February 21, 2026, through the registrar Gransy s.r.o. d/b/a subreg.cz, a provider frequently observed in fraudulent domain registrations. The domain resolves to the IP address 194.87.132.114, hosted on AS213035 (Serverion B.V.) in the Netherlands, a network segment with a history of hosting phishing and scam infrastructure. Security vendors on VirusTotal flagged the domain at a detection rate of 15/95, while three independent security blocklists, including PhishDestroy and MetaMask, have explicitly listed it as malicious. The domain also employs a Let’s Encrypt SSL certificate (identifier E8), a tactic often used to lend a false sense of legitimacy to fraudulent sites. Users who visited ethereum-trader.app or interacted with its content should take immediate remedial action. Any cryptocurrency wallets connected to the site must be considered compromised; users are advised to transfer assets to a new wallet using a clean device and revoke all prior wallet authorizations. System scans using updated security tools are recommended to detect potential malware or backdoors installed during the interaction. Additionally, users should monitor transaction histories for unauthorized activity and report the domain to relevant financial and cybersecurity authorities to aid in mitigation efforts. Given the high-risk classification and offline status, continued vigilance is necessary, as threat actors may re-deploy similar infrastructure under new domains.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260204-CF818B- Yakalanan sayfa başlığı
- Nemvarun™ | The Official & Updated Site【2026】
- PDF belgesi
- PDF kanıtı
Hukuki dayanak
Kanıtın tam metni
Acceptable Use Policy (AUP): The domain ethereum-trader.app is engaged in phishing activities, which directly contravenes the AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The registrar reserves the right to suspend or terminate services for violations, and the ongoing phishing operations constitute a clear breach of these terms.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. law prohibits unauthorized access and fraud in connection with computers, applicable to phishing schemes.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud using electronic communications, which encompasses phishing activities.
Anti-Phishing Consumer Protection Act: This legislation aims to combat phishing and protect consumers from fraudulent online schemes.
Regulatory Note: Failure to take immediate action against this domain may result in liability for facilitating illegal activities and could lead to regulatory scrutiny. Prompt compliance is essential to mitigate potential legal repercussions.
Data Coverage
Güvenlik Sinyalleri
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | ethereum-trader.app |
malicious | Sinkholed |
| OpenDNS | ethereum-trader.app |
phishing | Phishing Block |
| Hagezi Threat Feed | ethereum-trader.app |
malicious | Sinkholed |
| DNS4EU | ethereum-trader.app |
malicious | Sinkholed |
| DigiCert UltraDNS | ethereum-trader.app |
malicious | Sinkholed |
| Quad9 DNS | ethereum-trader.app |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of ethereum-trader.app · checked Mar 2, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin